Key Points

  • A smart contract audit is an independent review of a project's code that looks for bugs and security flaws before, or after, it handles real money.
  • Auditors combine manual line-by-line review with automated tools, testing and sometimes formal mathematical proofs.
  • An audit report lists findings by severity, from critical to informational, and says whether each one was fixed, acknowledged or left open.
  • An audit covers a specific version of the code at a specific time. Changes made afterwards are not covered unless they are audited too.
  • Audited protocols still get hacked. Treat an audit as one sign of care, alongside bug bounties, track record and how much control the team keeps.

Quick Answer

A smart contract audit is a security review in which independent specialists examine a project's code for flaws that could let attackers steal funds or break the system. The result is a report that lists each issue, rates its severity and records whether the team fixed it. Read an audit by checking who did it, which code it covered, and whether serious findings were actually resolved. The common misread is that "audited" means safe. An audit reduces risk, but it cannot prove code is free of bugs, and it says nothing about changes made after it ended.

What is a smart contract audit?

Smart contracts are programs on a blockchain that hold and move money automatically. Once deployed, many cannot easily be changed, and a single bug can let an attacker drain everything they hold. An audit is a structured attempt to find those bugs first.

Audits are carried out by specialist security firms, independent researchers or open competitions where many reviewers search the same code for rewards. Our guide to DeFi explains why this matters so much for protocols that hold user deposits.

How does a smart contract audit work?

  1. Scoping. The team and auditors agree which contracts, and which exact version of the code, will be reviewed. The version is usually fixed by a commit hash, a unique fingerprint of the code.
  2. Understanding the design. Auditors read the documentation and specification so they know what the code is meant to do.
  3. Automated analysis. Tools scan for known bug patterns, and fuzzing feeds the contracts large amounts of random input to find unexpected behaviour.
  4. Manual review. Reviewers read the code line by line, looking for logic errors, access control mistakes, price manipulation routes and economic attacks that tools miss.
  5. Testing and, sometimes, formal verification. Auditors write tests for edge cases. For critical code, formal verification uses mathematics to prove certain properties hold.
  6. Report. Findings are written up with a severity rating and a recommended fix.
  7. Fix review. The team fixes issues, and auditors check the fixes. The final report records what was resolved.
  8. Ongoing security. Good projects follow an audit with a public bug bounty and further audits whenever the code changes.

How do you read an audit report?

  • Who did it. Look for an established auditor with a public track record. A report from an unknown firm that only ever finds minor issues tells you little.
  • What was covered. Check the scope and commit hash. If the deployed contracts are different from the audited version, the audit does not cover what you are using.
  • Severity and status. Critical and high findings should be marked resolved. "Acknowledged" means the team accepted the risk without fixing it, and you should understand why.
  • Date. An audit from years ago may not reflect the code running today.
  • Centralisation notes. Many reports flag admin keys that can upgrade or pause contracts. That is a trust risk even if the code has no bugs.

Audit reports are normally published on the project's website or documentation, and the audit firm usually lists them too. If a project claims an audit but will not share the report, treat the claim as unverified.

Why do audited projects still get hacked?

Because an audit is limited by time, scope and the reviewers' knowledge. Common gaps include:

  • Code changed after the audit, or contracts deployed that were not in scope.
  • Economic and integration attacks, where each contract works as intended but the way they interact with prices, oracles or other protocols can be exploited.
  • Compromised keys, where an attacker steals the keys that control upgrades or treasuries. No code audit covers that.
  • Accepted risks, where findings were acknowledged but not fixed.

Several of the largest DeFi exploits have hit protocols that had been audited, which is why an audit should be one check among several. Our guide to rug pulls and honeypots covers the contract checks you can do yourself.

What else shows a project takes security seriously?

  • Multiple audits by different firms, especially after major upgrades.
  • A public bug bounty that pays researchers for responsibly reporting flaws.
  • Time-locked upgrades, so users can see and react to changes before they take effect.
  • A long, clean track record with significant funds held, which tests code in a way no review can.
  • Open, verified source code that anyone can read on a block explorer.

Frequently Asked Questions

How much does a smart contract audit cost?

It varies widely with the size and complexity of the code and the reputation of the auditor. A short, simple contract costs far less than a large protocol with many interacting contracts, which may need several audits.

Does an audit mean a token is a good investment?

No. An audit checks whether code works as intended. It says nothing about whether the token has demand, a sound business or a fair price.

Can I audit a contract myself?

Without a background in security engineering, not in any meaningful depth. You can still check basic facts: whether the code is verified, who controls it, and whether published audits match the deployed version.

What is a bug bounty?

A reward a project pays to people who find and responsibly report security flaws, rather than exploiting them. Large bounties give skilled researchers a reason to look.

Every call, scored

We publish each market call with its date and the condition that would prove it wrong, then score it when it resolves, misses included. Anyone can check.

See the record

Further Reading

This article is for education only and is not financial, investment or legal advice. Crypto assets are volatile and you can lose some or all of the money you put in. A security audit reduces but does not remove the risk of bugs, exploits or loss of funds. Do your own research and consider independent advice before making any financial decision.