Skip to content
AnalysisAU-2026-0274

Audits find what the scope allows them to find

Most losses this year came from code that was audited. The finding was outside the brief.

SeverityHigh

10 minSmart Contract Audits

It is tempting to read a large loss on audited code as an audit failure. Reading the engagement letters tells a different story: in the majority of cases the vulnerable interaction sat outside the reviewed scope — an upgrade path, an oracle dependency, a governance action, an off-chain component that signed something.

Scope is negotiated on price. A protocol that pays for two weeks of review on four contracts gets exactly that, and the report says so on page one.

What sits outside a typical scope

  • Upgrade and proxy mechanics, including who holds the keys and under what quorum.
  • Oracle behaviour under illiquidity — correct code fed a manipulated price.
  • Economic parameters that are safe at launch and unsafe at scale.
  • Off-chain signers and relayers, which are ordinary software with ordinary bugs.
The report was accurate. The question we were asked was too narrow, and we said so in it.
Partner at a contract audit firm

What to watch

Whether protocols start publishing scope alongside the report. A few now do, and it changes how a reader should weigh the badge.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined