# Smart-contract audits: reading the scope, findings and limits

A smart-contract audit is a structured review of specified code and assumptions at a particular revision. Its useful evidence is the scope, methods, findings and fix review. An audit does not prove the deployed system has no bugs, and a report for one version does not automatically cover later upgrades or integrations.

Evidence: [Uniswap v4 Core Audit](https://www.openzeppelin.com/news/uniswap-v4-core-audit); [Proxy contracts](https://docs.openzeppelin.com/contracts/5.x/api/proxy)

Canonical: https://degreesofsatoshi.com/encyclopedia/smart-contract-audits/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T15:08:18.373Z

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Revision:** OpenZeppelin’s cited v4 audit names reviewed commit d5d4957. ([Uniswap v4 Core Audit](https://www.openzeppelin.com/news/uniswap-v4-core-audit))
- **Findings:** Reports distinguish severity and resolution state. ([Uniswap v4 Core Audit](https://www.openzeppelin.com/news/uniswap-v4-core-audit))
- **Later changes:** Upgradeable implementations can change after a review. ([Proxy contracts](https://docs.openzeppelin.com/contracts/5.x/api/proxy))

## Start with the code and assumptions reviewed

A report should identify repositories, revisions, files, review dates and excluded components. Those details define what its conclusions can support. The OpenZeppelin Uniswap v4 Core Audit dated 27 August 2024 is an example of a report that names a code revision and enumerates its scope.

A protocol may depend on a router, oracle, token and web interface outside a particular core-contract review. The presence of the project’s name on the report does not imply every component was included.

Evidence: [Uniswap v4 Core Audit](https://www.openzeppelin.com/news/uniswap-v4-core-audit)

## Read the resolution and its evidence

A finding describes a weakness under stated conditions. A resolution can point to a patch or explain an accepted limitation. The resolution status matters alongside severity: “found” and “fixed” are distinct statements.

A practical comparison follows a finding to its proposed fix, the reviewer’s response and the deployment revision. A review of an earlier branch is useful evidence but not automatic evidence for a later deployment. This is an assessment method, not a claim that a particular live system is vulnerable.

Evidence: [Uniswap v4 Core Audit](https://www.openzeppelin.com/news/uniswap-v4-core-audit)

## A component review does not prove every composition

Standard components still require correct integration. For example, vault share accounting has rounding and donation-sensitive behavior that an integrator must understand. An interface standard does not eliminate those economic edge cases.

Later implementation upgrades, role changes or new dependencies can change the relevant system. Audits complement tests, monitoring and carefully bounded operations; they cannot turn an unbounded future claim of safety into a verified fact.

Evidence: [ERC-4626 security considerations](https://docs.openzeppelin.com/contracts/5.x/erc4626); [Proxy contracts](https://docs.openzeppelin.com/contracts/5.x/api/proxy)

## Questions

### Does “audited” mean a protocol cannot be exploited?

No. A report concerns a defined scope and revision and can leave assumptions or unresolved issues. Later changes and interactions can introduce behavior outside that review.

Evidence: [Uniswap v4 Core Audit](https://www.openzeppelin.com/news/uniswap-v4-core-audit); [Proxy contracts](https://docs.openzeppelin.com/contracts/5.x/api/proxy)

## Claims and scope

### smart-contract-audits-quick-answer

A smart-contract audit is a structured review of specified code and assumptions at a particular revision. Its useful evidence is the scope, methods, findings and fix review. An audit does not prove the deployed system has no bugs, and a report for one version does not automatically cover later upgrades or integrations.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

### smart-contract-audits-fact-revision

Revision: OpenZeppelin’s cited v4 audit names reviewed commit d5d4957.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

### smart-contract-audits-fact-findings

Findings: Reports distinguish severity and resolution state.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

### smart-contract-audits-fact-later-changes

Later changes: Upgradeable implementations can change after a review.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

## Sources

- [Uniswap v4 Core Audit](https://www.openzeppelin.com/news/uniswap-v4-core-audit) — OpenZeppelin Security. An actual audit identifies reviewed revisions, assumptions, findings and resolutions. Locator: Scope; Security Model and Trust Assumptions; Conclusion. Retrieved: 2026-10-02.
- [Proxy contracts](https://docs.openzeppelin.com/contracts/5.x/api/proxy) — OpenZeppelin. Proxy implementation changes and the authorization requirement. Locator: TransparentUpgradeableProxy; UUPSUpgradeable. Retrieved: 2026-10-02.
- [ERC-4626 security considerations](https://docs.openzeppelin.com/contracts/5.x/erc4626) — OpenZeppelin. Share conversion, rounding and donation-based exchange-rate manipulation. Locator: Security concern: Inflation attack; Custom behavior. Retrieved: 2026-10-02.

## Revision history

- 2026-10-02: First publication after primary-source research and independent automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Smart-contract audits: reading the scope, findings and limits.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/smart-contract-audits/
