Skip to content
BITBRIEF

Institutional research · AI · Cybersecurity · Digital assets

Vol. 01 · No. 13

Smart contract audit

A review of deployed or deployable contract code for defects that let value be taken, frozen or blocked, delivered as findings ranked by severity.

An audit is scoped work, not a certificate. It covers named files over a named period and reports what was found in them. Everything outside that scope is untested, and the report normally says so.

The trust assumptions matter more than the findings

A good report lists what the design assumes rather than proves — that no more than a third of validator power is compromised, that a sequencer stays honest, that an off-chain component manages roles correctly. Contracts can be sound against their assumptions while the assumptions carry all the risk. For anyone sizing exposure, that list is the actual risk register.

The defects that do not look like defects

The hardest class is state divergence: two places hold what should be the same fact and only one is kept current. Every piece reads correctly on its own, and the defect lives in the assumption that a cached copy is maintained. One such bug let any account claim administrative control over 82 token markers because a stale supply field compared equal to a new account's zero balance. The fix was one line.

All 30 terms