BTC…ETH…ETH gas…Fear & Greed…Live data · not advice

Crypto Lexicon

Smart Contract Audits

An audit covers one commit, one file list, one date. What scope statements exclude, what static analysis misses, and how to read a report properly.

An Audit Has an Exact Scope

A serious report says precisely what was examined, usually a repository at a specific commit, sometimes an archive pinned by checksum with a file by file appendix. That precision is the whole point. Anything outside the manifest was not reviewed, and good reports say so out loud.

A published OpenZeppelin review of a euro stablecoin states that the transparent proxy and the proxy administrator that govern upgrades, the multi signature wallets, and the off chain governance procedures all sat outside the review boundary. Sit with that for a moment. The contracts were audited. The machinery capable of replacing those contracts was not.

What Tools Can and Cannot Find

Automated analysis covers the classes somebody bothered to write a detector for. Slither, a widely used static analysis framework, ships detectors across roughly a hundred vulnerability categories: reentrancy, uninitialised variables, unchecked transfers and similar.

Those are patterns. A design that is internally consistent but economically nonsense, an incentive that quietly inverts under stress, or a governance path that lets one address drain a pool, are not patterns, and no detector is looking for them. A clean automated run means no known pattern matched. It is a spellcheck, not a proofread.

The Failure Mode Audits Do Not Address

Most losses are not ingenious code exploits at all. Trail of Bits, reviewing verified incidents, found that 43.8 percent of stolen funds came from compromised keys, more than any other verified attack type by a factor of five. No amount of reading Solidity stops somebody obtaining a signing key, and key management is usually outside the scope statement anyway.

How to Read a Report

The practical rule: open the report rather than admire the badge. Find the commit or file list, find the scope exclusions, then check whether the contract you are about to use is still running that implementation. The standardised proxy storage slots make that last check possible without asking anyone. If a project cannot say which commit was audited, or the live implementation no longer matches it, then "audited" is a statement about history, not about the thing currently holding your money.

Knowledge check

Three quick questions on this entry. Pick an answer to see whether it is right.

Question 1 of 3Which description matches Smart Contract Audits?

Question 2 of 3What does an audit report actually cover?

Question 3 of 3Which of these also belongs to Consensus & Security?

Frequently asked question

What is Smart Contract Audits?

An audit covers one commit, one file list, one date. What scope statements exclude, what static analysis misses, and how to read a report properly.

The Letter

One clear letter, every week.

Plain analysis of crypto infrastructure, markets and security. No price calls, no referral links, no hype.

Unsubscribe at any time. Read the privacy notice.

Reader reviews

Did you like what you just read?

Tell other readers what worked, what did not, and who you would recommend it to. Every review is read by a human before it is published, and critical reviews get the same treatment as glowing ones.

Leave a review →