Smart contract audit: what it checks and what it proves
A smart contract audit reviews code for bugs and security flaws before launch. The report rates issues and shows fixes, but it is not a guarantee.

On this page
- Auditors rate findings by severity and note later fixes.
- Reports often appear on a project's website or documentation.
- An audit is not a guarantee, and audited code can still be hacked.
A smart contract audit is a review of blockchain code for bugs and security flaws before launch. Auditors inspect the code by hand and with tools, then publish a report for the project.
Ethereum launched in July 2015 and made these programs common. A project usually pays an outside firm before launch or a major update.
What does an audit check?
Auditors read the code by hand and run tools to find flaws. They check money, permissions and outside calls. The report rates each issue by severity and shows whether the team fixed it.
How do people use audit reports?
Projects often post audit reports on their websites or in their documentation. The report shows what the auditors checked, what they found and how the team responded.
What an audit cannot guarantee
An audit is a review at one point in time, not a guarantee of safety. Audited contracts can still be hacked if the auditors miss a flaw or if the team changes the code later. A report is not a government approval.
Audit versus formal verification
Formal verification uses mathematics to prove that a contract behaves as intended under defined rules. A smart contract audit is a human review that mixes manual reading with tools. The two can be used together, but they are not the same.
Frequently asked questions
It depends on the code's size and complexity. A small contract can take days, while a large project can take weeks or months.
Security firms and independent auditors usually perform them. Some projects also run bug bounty programs to get more people looking for flaws.
Yes, a team can order an audit after launch. The review then covers the deployed code.





