Skip to content
SEC-02

Smart Contract Audits

Audit practice, disclosed exploits and what the post-mortems teach.

Recent

  1. Field reportAU-2026-0281

    A protocol built on XML signatures

    Trail of Bits argues SAML should be deprecated: it is comprehensible on its own terms and rests on a signature-validation layer that has defeated most implementations.

    3 minSource: Trail of Bits

  2. Field reportAU-2026-0280

    Sixty findings, none critical, in Miden

    An OpenZeppelin review of the Miden contract library reports no critical or high issues and eleven medium ones, most of them about authorisation.

    3 minSource: OpenZeppelin

  3. Field reportAU-2026-0279

    A zero that matched another zero

    One stale field let any account claim admin over 82 markers on Provenance. The check compared a supply that was never written back.

    SeverityHigh

    3 minSource: Trail of Bits

  4. Field reportAU-2026-0278

    Two files, eleven findings, five assumptions

    OpenZeppelin's review of the TxFlow bridge found no critical or high issues. The list of things the bridge takes on trust is longer than the list of bugs.

    SeverityMedium

    3 minSource: OpenZeppelin

  5. Field reportAU-2026-0277

    A freeze that burning could walk around

    Thirty-two findings on a single gold-backed token contract, and the high-severity one was a compliance control with three ways past it.

    3 minSource: OpenZeppelin

  6. AnalysisAU-2026-0276

    A control at the interface is not a control

    OpenZeppelin sets out how institutions gate participation on public chains, and where the enforcement has to live to count.

    2 minSource: OpenZeppelin

  7. Field reportAU-2026-0275

    Nineteen findings, none critical, six still open

    OpenZeppelin's review of the Across V5 bridging extensions is more useful for what stayed unresolved than for what was fixed.

    2 minSource: OpenZeppelin

  8. AnalysisAU-2026-0274

    Audits find what the scope allows them to find

    Most losses this year came from code that was audited. The finding was outside the brief.

    SeverityHigh

    10 min

  9. Research noteAU-2026-0268

    Formal verification quietly left the lab

    Specification effort still dominates, but the tooling is no longer the bottleneck.

    SeverityLow

    7 min

  10. AnalysisAU-2026-0261

    Reentrancy is back, through token callbacks

    The classic pattern was closed. Hook-bearing token standards reopened it sideways.

    SeverityCritical

    6 min

  11. Market briefAU-2026-0255

    Bug bounties still price below the exploit

    When the payout is a fraction of what the bug is worth, disclosure is a donation.

    SeverityModerate

    5 min