How to Read a Smart Contract Audit Report
An audit badge tells you almost nothing. The scope section tells you nearly everything — which commit was reviewed, which contracts were in it, and what was excluded.
Searches every incident record, jurisdiction page, glossary term and guide.
Practical guides to crypto security and the rules around it, written to be useful rather than reassuring. Every guide states plainly what it does not protect you from — because a security guide that only lists its own strengths is marketing. Nothing here is financial, legal, tax or security advice.
12 articles
An audit badge tells you almost nothing. The scope section tells you nearly everything — which commit was reviewed, which contracts were in it, and what was excluded.
Most deployed contracts are upgradeable, which means someone can change what they do to funds already held. That control chain is public…
"Regulated" is not a property a firm can assert about itself. It means a named authority, a named permission category, and an…
Whether you own the assets or merely have a claim against the company is decided by paperwork written long before the failure…
Read enough incident records and the same handful of shapes recur. Knowing the shapes is more useful than knowing the individual events.
Cold storage describes where a key is held. It says nothing about how a transaction gets approved — which is where several…
Bridges account for several of the largest losses on record. The reason is structural, and it is visible in every one of…
The word "regulated" carries very different weight depending on which regulator, for what, and under which regime. Here is how to read…
A token approval is a standing authorisation that outlives the transaction that created it. Here is how to see what yours have…
The most expensive failures in crypto have not broken cryptography. They changed what the signer was shown. Here is what to look…