Crypto glossary

Audit

An audit is a structured security review of a smart contract's code, logic and architecture, done by specialists who look for bugs and design flaws before or after the contract goes live.

Auf Deutsch lesen

What auditors do

Auditors read the code line by line, test it with automated tools and try to think like attackers. They check access controls, arithmetic, external calls, price oracle use and the economic logic of the protocol. Some also use formal verification, a mathematical method to prove that certain properties always hold.

The result is a report that lists findings by severity, such as critical, high, medium and low, together with the team's response and whether each issue was fixed.

How to read an audit report

Check what was in scope: which contracts, which version and which commit of the code. A report about an older version says little about what is deployed now. Look at whether critical and high findings were resolved or merely acknowledged. Note who did the audit and whether the report is published on the auditor's own website, not only as a PDF on the project's site.

Why an audit is not a guarantee

Audits are limited by time, budget and the auditors' skill. They cover the code as it was at one point in time; later upgrades, new integrations or changes in market conditions can create new risks. Many exploited protocols had been audited, sometimes several times.

An audit also does not judge the team's intentions. A contract can be bug-free and still give its owners the power to mint unlimited tokens or withdraw user funds. Scammers sometimes advertise audits that are superficial, fake or about different code.

What else to look for

Multiple independent audits, an active bug bounty, a long track record with real value at stake, limited and time-delayed admin powers, and open-source code all add confidence. None of them alone makes a protocol safe.

Ask Coach about it

Coach is the AI on AtenaCrypto. It explains crypto with live market data, in plain words.

How do I check whether a protocol's audit covers the contracts that are actually deployed?Ask Coach →

Frequently asked questions

Does an audited project mean it is safe to invest in?

No. An audit only reviews code security at one point in time. It says nothing about whether the token or project is a good investment.

How can I tell if an audit is real?

Look for the report on the auditor's own website or repository and compare the audited contract addresses or commit with what is deployed.

What is the difference between an audit and a bug bounty?

An audit is a paid, time-limited review by a chosen firm. A bug bounty is an ongoing open offer that rewards anyone who responsibly reports a vulnerability.

Related terms

Smart Contract RiskExploitBug BountySmart ContractDue DiligenceRug Pull

Learn it step by step

AC Learning explains these ideas in interactive lessons — the first eight sections are free.

Open AC Learning → Create a free account

All glossary terms · Educational reference only — not investment, legal, tax or financial advice.