Skip to content
DeFi & Web3Beginner

Smart contract audit: what it checks and what it proves

A smart contract audit reviews code for bugs and security flaws before launch. The report rates issues and shows fixes, but it is not a guarantee.

Vahe HakobyanVahe HakobyanEditor-in-chief Updated Oct 6, 20263 min readFact-checked
A dark navy background with a glowing magnifying glass, glass code block, shield and padlock.
Illustration: World-Crypt
On this page
Key takeaways
  • Auditors rate findings by severity and note later fixes.
  • Reports often appear on a project's website or documentation.
  • An audit is not a guarantee, and audited code can still be hacked.

A smart contract audit is a review of blockchain code for bugs and security flaws before launch. Auditors inspect the code by hand and with tools, then publish a report for the project.

Ethereum launched in July 2015 and made these programs common. A project usually pays an outside firm before launch or a major update.

What does an audit check?

Auditors read the code by hand and run tools to find flaws. They check money, permissions and outside calls. The report rates each issue by severity and shows whether the team fixed it.

How auditors inspect code
Criterion Manual review Tools
Focus Logic and design Known patterns
Limit Depends on skill Can miss new logic

How do people use audit reports?

Projects often post audit reports on their websites or in their documentation. The report shows what the auditors checked, what they found and how the team responded.

Reading an audit report

  • Open the project's website or documentation.
  • Find the audit report and check its date.
  • Read the severity ratings and the team's responses.

What an audit cannot guarantee

An audit is a review at one point in time, not a guarantee of safety. Audited contracts can still be hacked if the auditors miss a flaw or if the team changes the code later. A report is not a government approval.

Audit versus formal verification

Formal verification uses mathematics to prove that a contract behaves as intended under defined rules. A smart contract audit is a human review that mixes manual reading with tools. The two can be used together, but they are not the same.

Two ways to check code
Criterion Smart contract audit Formal verification
Method Manual review and tools Mathematical proof
Lead Auditors Engineers with a model
Limit Can miss issues Only covers the model

Frequently asked questions

It depends on the code's size and complexity. A small contract can take days, while a large project can take weeks or months.

Security firms and independent auditors usually perform them. Some projects also run bug bounty programs to get more people looking for flaws.

Yes, a team can order an audit after launch. The review then covers the deployed code.

Was this guide helpful?
Written byVahe HakobyanVahe Hakobyan is the editor-in-chief of World-Crypt. He covers bitcoin, markets and regulation, and leads the newsroom that fact-checks every story before it goes live.