{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "smart-contract-audits",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/smart-contract-audits/",
  "collection": "defi",
  "title": "Smart-contract audits: reading the scope, findings and limits",
  "description": "Learn what a security audit actually reviewed, how fixes relate to deployed code, and why an audit is evidence about a scope rather than a guarantee.",
  "aliases": [
    "DeFi audit"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T15:08:18.373Z",
    "dataAsOf": null
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "A smart-contract audit is a structured review of specified code and assumptions at a particular revision. Its useful evidence is the scope, methods, findings and fix review. An audit does not prove the deployed system has no bugs, and a report for one version does not automatically cover later upgrades or integrations.",
    "claimId": "smart-contract-audits-quick-answer",
    "sourceIds": [
      "audit",
      "proxy"
    ]
  },
  "keyFacts": [
    {
      "label": "Revision",
      "value": "OpenZeppelin’s cited v4 audit names reviewed commit d5d4957.",
      "sourceIds": [
        "audit"
      ],
      "id": "revision",
      "claimId": "smart-contract-audits-fact-revision"
    },
    {
      "label": "Findings",
      "value": "Reports distinguish severity and resolution state.",
      "sourceIds": [
        "audit"
      ],
      "id": "findings",
      "claimId": "smart-contract-audits-fact-findings"
    },
    {
      "label": "Later changes",
      "value": "Upgradeable implementations can change after a review.",
      "sourceIds": [
        "proxy"
      ],
      "id": "later-changes",
      "claimId": "smart-contract-audits-fact-later-changes"
    }
  ],
  "prerequisites": [
    "protocol-upgrades-and-admin-powers"
  ],
  "sections": [
    {
      "id": "scope",
      "heading": "Start with the code and assumptions reviewed",
      "paragraphs": [
        "A report should identify repositories, revisions, files, review dates and excluded components. Those details define what its conclusions can support. The OpenZeppelin Uniswap v4 Core Audit dated 27 August 2024 is an example of a report that names a code revision and enumerates its scope.",
        "A protocol may depend on a router, oracle, token and web interface outside a particular core-contract review. The presence of the project’s name on the report does not imply every component was included."
      ],
      "sourceIds": [
        "audit"
      ]
    },
    {
      "id": "findings",
      "heading": "Read the resolution and its evidence",
      "paragraphs": [
        "A finding describes a weakness under stated conditions. A resolution can point to a patch or explain an accepted limitation. The resolution status matters alongside severity: “found” and “fixed” are distinct statements.",
        "A practical comparison follows a finding to its proposed fix, the reviewer’s response and the deployment revision. A review of an earlier branch is useful evidence but not automatic evidence for a later deployment. This is an assessment method, not a claim that a particular live system is vulnerable."
      ],
      "sourceIds": [
        "audit"
      ]
    },
    {
      "id": "system",
      "heading": "A component review does not prove every composition",
      "paragraphs": [
        "Standard components still require correct integration. For example, vault share accounting has rounding and donation-sensitive behavior that an integrator must understand. An interface standard does not eliminate those economic edge cases.",
        "Later implementation upgrades, role changes or new dependencies can change the relevant system. Audits complement tests, monitoring and carefully bounded operations; they cannot turn an unbounded future claim of safety into a verified fact."
      ],
      "sourceIds": [
        "vaultsecurity",
        "proxy"
      ]
    }
  ],
  "faq": [
    {
      "question": "Does “audited” mean a protocol cannot be exploited?",
      "answer": "No. A report concerns a defined scope and revision and can leave assumptions or unresolved issues. Later changes and interactions can introduce behavior outside that review.",
      "sourceIds": [
        "audit",
        "proxy"
      ]
    }
  ],
  "claims": [
    {
      "id": "smart-contract-audits-quick-answer",
      "articleSlug": "smart-contract-audits",
      "statement": "A smart-contract audit is a structured review of specified code and assumptions at a particular revision. Its useful evidence is the scope, methods, findings and fix review. An audit does not prove the deployed system has no bugs, and a report for one version does not automatically cover later upgrades or integrations.",
      "sourceIds": [
        "source-3665c27c1b3e405a",
        "source-16bb921e662a5173"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-3665c27c1b3e405a",
          "locator": "Scope; Security Model and Trust Assumptions; Conclusion"
        },
        {
          "sourceId": "source-16bb921e662a5173",
          "locator": "TransparentUpgradeableProxy; UUPSUpgradeable"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T15:08:18.373Z",
        "reviewer": "automated independent verification",
        "notes": [
          "Read OpenZeppelin’s August27,2024 Uniswap v4 report, exact scope commitd5d4957, trust assumptions, severity/resolution states and conclusion. Read proxy upgrade documentation for later-change scope.",
          "The article preserves report/date/revision boundaries and states that an audit is not proof against exploitation or coverage of every future integration."
        ]
      }
    },
    {
      "id": "smart-contract-audits-fact-revision",
      "articleSlug": "smart-contract-audits",
      "statement": "Revision: OpenZeppelin’s cited v4 audit names reviewed commit d5d4957.",
      "sourceIds": [
        "source-3665c27c1b3e405a"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-3665c27c1b3e405a",
          "locator": "Scope; Security Model and Trust Assumptions; Conclusion"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T15:08:18.373Z",
        "reviewer": "automated independent verification",
        "notes": [
          "Read OpenZeppelin’s August27,2024 Uniswap v4 report, exact scope commitd5d4957, trust assumptions, severity/resolution states and conclusion. Read proxy upgrade documentation for later-change scope.",
          "The article preserves report/date/revision boundaries and states that an audit is not proof against exploitation or coverage of every future integration."
        ]
      }
    },
    {
      "id": "smart-contract-audits-fact-findings",
      "articleSlug": "smart-contract-audits",
      "statement": "Findings: Reports distinguish severity and resolution state.",
      "sourceIds": [
        "source-3665c27c1b3e405a"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-3665c27c1b3e405a",
          "locator": "Scope; Security Model and Trust Assumptions; Conclusion"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T15:08:18.373Z",
        "reviewer": "automated independent verification",
        "notes": [
          "Read OpenZeppelin’s August27,2024 Uniswap v4 report, exact scope commitd5d4957, trust assumptions, severity/resolution states and conclusion. Read proxy upgrade documentation for later-change scope.",
          "The article preserves report/date/revision boundaries and states that an audit is not proof against exploitation or coverage of every future integration."
        ]
      }
    },
    {
      "id": "smart-contract-audits-fact-later-changes",
      "articleSlug": "smart-contract-audits",
      "statement": "Later changes: Upgradeable implementations can change after a review.",
      "sourceIds": [
        "source-16bb921e662a5173"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-16bb921e662a5173",
          "locator": "TransparentUpgradeableProxy; UUPSUpgradeable"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T15:08:18.373Z",
        "reviewer": "automated independent verification",
        "notes": [
          "Read OpenZeppelin’s August27,2024 Uniswap v4 report, exact scope commitd5d4957, trust assumptions, severity/resolution states and conclusion. Read proxy upgrade documentation for later-change scope.",
          "The article preserves report/date/revision boundaries and states that an audit is not proof against exploitation or coverage of every future integration."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "audit",
      "label": "Uniswap v4 Core Audit",
      "publisher": "OpenZeppelin Security",
      "url": "https://www.openzeppelin.com/news/uniswap-v4-core-audit",
      "locator": "Scope; Security Model and Trust Assumptions; Conclusion",
      "note": "An actual audit identifies reviewed revisions, assumptions, findings and resolutions.",
      "version": "2024-08-27 report; reviewed commit d5d4957",
      "checkedAt": "2026-10-02",
      "recordId": "source-3665c27c1b3e405a",
      "contentSha256": null
    },
    {
      "id": "proxy",
      "label": "Proxy contracts",
      "publisher": "OpenZeppelin",
      "url": "https://docs.openzeppelin.com/contracts/5.x/api/proxy",
      "locator": "TransparentUpgradeableProxy; UUPSUpgradeable",
      "note": "Proxy implementation changes and the authorization requirement.",
      "version": "OpenZeppelin Contracts 5.x",
      "checkedAt": "2026-10-02",
      "recordId": "source-16bb921e662a5173",
      "contentSha256": null
    },
    {
      "id": "vaultsecurity",
      "label": "ERC-4626 security considerations",
      "publisher": "OpenZeppelin",
      "url": "https://docs.openzeppelin.com/contracts/5.x/erc4626",
      "locator": "Security concern: Inflation attack; Custom behavior",
      "note": "Share conversion, rounding and donation-based exchange-rate manipulation.",
      "version": "OpenZeppelin Contracts 5.x",
      "checkedAt": "2026-10-02",
      "recordId": "source-e18b8696025f65d0",
      "contentSha256": null
    }
  ],
  "related": {
    "articles": [
      "documented-defi-exploits",
      "protocol-upgrades-and-admin-powers",
      "defi-composability"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and independent automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Smart-contract audits: reading the scope, findings and limits.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/smart-contract-audits/"
}
