Encyclopedia DeFi · Entry 73
Smart-contract audits: reading the scope, findings and limits
In this article
At a glance
Key facts
Start with the code and assumptions reviewed
A report should identify repositories, revisions, files, review dates and excluded components. Those details define what its conclusions can support. The OpenZeppelin Uniswap v4 Core Audit dated 27 August 2024 is an example of a report that names a code revision and enumerates its scope.
A protocol may depend on a router, oracle, token and web interface outside a particular core-contract review. The presence of the project’s name on the report does not imply every component was included.
Read the resolution and its evidence
A finding describes a weakness under stated conditions. A resolution can point to a patch or explain an accepted limitation. The resolution status matters alongside severity: “found” and “fixed” are distinct statements.
A practical comparison follows a finding to its proposed fix, the reviewer’s response and the deployment revision. A review of an earlier branch is useful evidence but not automatic evidence for a later deployment. This is an assessment method, not a claim that a particular live system is vulnerable.
A component review does not prove every composition
Standard components still require correct integration. For example, vault share accounting has rounding and donation-sensitive behavior that an integrator must understand. An interface standard does not eliminate those economic edge cases.
Later implementation upgrades, role changes or new dependencies can change the relevant system. Audits complement tests, monitoring and carefully bounded operations; they cannot turn an unbounded future claim of safety into a verified fact.
Direct answers
Questions people ask
Does “audited” mean a protocol cannot be exploited?
No. A report concerns a defined scope and revision and can leave assumptions or unresolved issues. Later changes and interactions can introduce behavior outside that review.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
A smart-contract audit is a structured review of specified code and assumptions at a particular revision. Its useful evidence is the scope, methods, findings and fix review. An audit does not prove the deployed system has no bugs, and a report for one version does not automatically cover later upgrades or integrations.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimRevision: OpenZeppelin’s cited v4 audit names reviewed commit d5d4957.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimFindings: Reports distinguish severity and resolution state.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimLater changes: Upgradeable implementations can change after a review.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimRevision history
- — First publication after primary-source research and independent automated verification.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- Uniswap v4 Core AuditOpenZeppelin Security
An actual audit identifies reviewed revisions, assumptions, findings and resolutions.
Locator: Scope; Security Model and Trust Assumptions; Conclusion · Version / scope: 2024-08-27 report; reviewed commit d5d4957 · Retrieved: 2026-10-02Open source - Proxy contractsOpenZeppelin
Proxy implementation changes and the authorization requirement.
Locator: TransparentUpgradeableProxy; UUPSUpgradeable · Version / scope: OpenZeppelin Contracts 5.x · Retrieved: 2026-10-02Open source - ERC-4626 security considerationsOpenZeppelin
Share conversion, rounding and donation-based exchange-rate manipulation.
Locator: Security concern: Inflation attack; Custom behavior · Version / scope: OpenZeppelin Contracts 5.x · Retrieved: 2026-10-02Open source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Smart-contract audits: reading the scope, findings and limits.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/smart-contract-audits/