Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia DeFi · Entry 73

Smart-contract audits: reading the scope, findings and limits

Theme
DeFi
Sources
3 cited records
Reading time
About 3 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for Smart-contract audits: reading the scope, findings and limits
FactDetailSource
RevisionOpenZeppelin’s cited v4 audit names reviewed commit d5d4957.[1]
FindingsReports distinguish severity and resolution state.[1]
Later changesUpgradeable implementations can change after a review.[2]
01

Start with the code and assumptions reviewed

A report should identify repositories, revisions, files, review dates and excluded components. Those details define what its conclusions can support. The OpenZeppelin Uniswap v4 Core Audit dated 27 August 2024 is an example of a report that names a code revision and enumerates its scope.

A protocol may depend on a router, oracle, token and web interface outside a particular core-contract review. The presence of the project’s name on the report does not imply every component was included.

02

Read the resolution and its evidence

A finding describes a weakness under stated conditions. A resolution can point to a patch or explain an accepted limitation. The resolution status matters alongside severity: “found” and “fixed” are distinct statements.

A practical comparison follows a finding to its proposed fix, the reviewer’s response and the deployment revision. A review of an earlier branch is useful evidence but not automatic evidence for a later deployment. This is an assessment method, not a claim that a particular live system is vulnerable.

03

A component review does not prove every composition

Standard components still require correct integration. For example, vault share accounting has rounding and donation-sensitive behavior that an integrator must understand. An interface standard does not eliminate those economic edge cases.

Later implementation upgrades, role changes or new dependencies can change the relevant system. Audits complement tests, monitoring and carefully bounded operations; they cannot turn an unbounded future claim of safety into a verified fact.

Direct answers

Questions people ask

Does “audited” mean a protocol cannot be exploited?

No. A report concerns a defined scope and revision and can leave assumptions or unresolved issues. Later changes and interactions can introduce behavior outside that review.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

A smart-contract audit is a structured review of specified code and assumptions at a particular revision. Its useful evidence is the scope, methods, findings and fix review. An audit does not prove the deployed system has no bugs, and a report for one version does not automatically cover later upgrades or integrations.

Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.

Link to this claim
Revision: OpenZeppelin’s cited v4 audit names reviewed commit d5d4957.

Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.

Link to this claim
Findings: Reports distinguish severity and resolution state.

Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.

Link to this claim
Later changes: Upgradeable implementations can change after a review.

Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.

Link to this claim
Revision history
  1. — First publication after primary-source research and independent automated verification.

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. Uniswap v4 Core AuditOpenZeppelin Security

    An actual audit identifies reviewed revisions, assumptions, findings and resolutions.

    Locator: Scope; Security Model and Trust Assumptions; Conclusion · Version / scope: 2024-08-27 report; reviewed commit d5d4957 · Retrieved: 2026-10-02Open source
  2. Proxy contractsOpenZeppelin

    Proxy implementation changes and the authorization requirement.

    Locator: TransparentUpgradeableProxy; UUPSUpgradeable · Version / scope: OpenZeppelin Contracts 5.x · Retrieved: 2026-10-02Open source
  3. ERC-4626 security considerationsOpenZeppelin

    Share conversion, rounding and donation-based exchange-rate manipulation.

    Locator: Security concern: Inflation attack; Custom behavior · Version / scope: OpenZeppelin Contracts 5.x · Retrieved: 2026-10-02Open source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “Smart-contract audits: reading the scope, findings and limits.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/smart-contract-audits/