Crypto Lexicon
Smart Contract Audits
An audit covers one commit, one file list, one date. What scope statements exclude, what static analysis misses, and how to read a report properly.
An Audit Has an Exact Scope
A serious report says precisely what was examined, usually a repository at a specific commit, sometimes an archive pinned by checksum with a file by file appendix. That precision is the whole point. Anything outside the manifest was not reviewed, and good reports say so out loud.
A published OpenZeppelin review of a euro stablecoin states that the transparent proxy and the proxy administrator that govern upgrades, the multi signature wallets, and the off chain governance procedures all sat outside the review boundary. Sit with that for a moment. The contracts were audited. The machinery capable of replacing those contracts was not.
What Tools Can and Cannot Find
Automated analysis covers the classes somebody bothered to write a detector for. Slither, a widely used static analysis framework, ships detectors across roughly a hundred vulnerability categories: reentrancy, uninitialised variables, unchecked transfers and similar.
Those are patterns. A design that is internally consistent but economically nonsense, an incentive that quietly inverts under stress, or a governance path that lets one address drain a pool, are not patterns, and no detector is looking for them. A clean automated run means no known pattern matched. It is a spellcheck, not a proofread.
The Failure Mode Audits Do Not Address
Most losses are not ingenious code exploits at all. Trail of Bits, reviewing verified incidents, found that 43.8 percent of stolen funds came from compromised keys, more than any other verified attack type by a factor of five. No amount of reading Solidity stops somebody obtaining a signing key, and key management is usually outside the scope statement anyway.
How to Read a Report
The practical rule: open the report rather than admire the badge. Find the commit or file list, find the scope exclusions, then check whether the contract you are about to use is still running that implementation. The standardised proxy storage slots make that last check possible without asking anyone. If a project cannot say which commit was audited, or the live implementation no longer matches it, then "audited" is a statement about history, not about the thing currently holding your money.
Knowledge check
Three quick questions on this entry. Pick an answer to see whether it is right.
Question 1 of 3Which description matches Smart Contract Audits?
Question 2 of 3What does an audit report actually cover?
Question 3 of 3Which of these also belongs to Consensus & Security?
Frequently asked question
What is Smart Contract Audits?
An audit covers one commit, one file list, one date. What scope statements exclude, what static analysis misses, and how to read a report properly.