Who produces the fact you are relying on, and can they be reached?
The CFTC published a sentence this week that is more useful than the advisory it appears in. Event contracts settling on whether a person says a word carry heightened manipulation risk, it says, because settlement turns on conduct "that may be neither independently generated nor externally verifiable."
That is a general test, and once you have it, the rest of today's items line up behind it.
A prediction market. The settlement fact is a human utterance. Someone holding a position can pay for it to happen, and there may be no authoritative record of whether it did — which venue, which phrasing, which timestamp. Not independently generated, not externally verifiable, and the regulator says so.
A wallet on an iPhone. The fact a user relies on is "apps cannot read each other's Keychain". That fact is produced by the operating system vendor, and nothing on the device lets a user verify it. FomoPeek's two hidden modules did not break cryptography; they broke the assumption, and the assumption was the only thing standing between a read-only tracker and somebody's seed phrase.
An audit request on Kusama. The proposers say plainly that partners take a project seriously once an auditor has looked at the code. Not because the audit proves the code correct — it cannot — but because it is the only externally generated signal available about a codebase nobody has time to read. The market pays for verifiability, not for security.
Three domains, one structure: somewhere in every arrangement there is a fact that the parties cannot produce themselves, and the quality of the arrangement is the quality of whoever produces it.

What follows is a question worth asking of anything you build or use.
Name the producer. For a price feed it is the oracle set. For a wallet it is the OS vendor and the app review process. For a DeFi position it may be a governance vote. If you cannot name the party, you have not found the trust assumption — you have just stopped looking.
Ask whether a participant can reach them. This is the CFTC's actual test, and it is sharper than "is it decentralised". A settlement source that is technically distributed but economically reachable by one large holder is worse than a single honest publisher.
Then ask what happens when they are wrong rather than malicious. Most failures are not manipulation. The iOS case is a vendor whose isolation guarantee had eight holes in it, and the users who lost money were not targeted by an adversary who beat cryptography; they installed a tracker.
The uncomfortable conclusion, and it is the same one every time: "trustless" describes the settlement layer, never the thing being settled. A chain can guarantee that a transfer happened exactly as signed. It cannot tell you whether the person said the word, whether the app was what it claimed, or whether the code does what the comment says. Those facts come from somewhere else, and that somewhere is the part worth auditing.
⚠️ Nothing here is investment advice. These are structural observations from published documents.