Audits find what the scope allows them to find
Most losses this year came from code that was audited. The finding was outside the brief.
SeverityHigh
10 minSmart Contract Audits
It is tempting to read a large loss on audited code as an audit failure. Reading the engagement letters tells a different story: in the majority of cases the vulnerable interaction sat outside the reviewed scope — an upgrade path, an oracle dependency, a governance action, an off-chain component that signed something.
Scope is negotiated on price. A protocol that pays for two weeks of review on four contracts gets exactly that, and the report says so on page one.
What sits outside a typical scope
- Upgrade and proxy mechanics, including who holds the keys and under what quorum.
- Oracle behaviour under illiquidity — correct code fed a manipulated price.
- Economic parameters that are safe at launch and unsafe at scale.
- Off-chain signers and relayers, which are ordinary software with ordinary bugs.
The report was accurate. The question we were asked was too narrow, and we said so in it.
What to watch
Whether protocols start publishing scope alongside the report. A few now do, and it changes how a reader should weigh the badge.