Library · Crypto, word by word · Scams and security
What is a smart contract audit?
A smart contract audit is a review of the code behind a crypto app or token by outside security reviewers, looking for bugs and design errors before or after it goes live. The result is usually a public report listing the problems found and whether they were fixed.
What it means for you
An audit is a review at one point in time, not a promise: Ethereum's own developer docs say audits do not catch every bug. Check the date, which version of the code was reviewed, and whether the issues listed were fixed. Code changed after the audit, or admin keys that can change the contract, sit outside what the audit covered.
A common mistake: “The project is audited, so the contract is secure.”
In fact: An audit reviews one version of the code at one time and, as Ethereum's docs say, will not catch every bug. Code upgraded afterwards, or admin keys able to change it, sit outside what the report covers.
How it works
Auditors read a fixed version of the code, run tests and analysis tools, and report weaknesses such as reentrancy or missing access controls, ranked by severity. Ethereum's developer docs say audits will not catch every bug and are mainly an extra round of review. Other layers sit beside them: bug bounties that pay people who report flaws, and formal verification, which can mathematically prove that code meets a written specification. Many contracts are upgradeable through a proxy, which lets the logic be replaced later; whoever controls that upgrade, often an admin key or multisig, can change code the audit never saw.
Source: ethereum.org: Smart contract security · checked 4 October 2026
Related words
Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.