A review of contract source code by a third party against known vulnerability classes and the protocol’s intended behaviour.
Why it matters
An audit is evidence that someone competent looked, not a guarantee. Euler had been audited multiple times; the defect was a missing check on a path reviewers did not read as risk-bearing. The Curve incident could not have been found by source review at all, because the compiler was at fault.
What you can check
An audit report has a scope section, and it is the most informative part. It states which commit was reviewed, which contracts were in scope, and which were not. Code deployed after the reviewed commit was not audited, whatever the badge on the website says.
Where it showed up
Records in the Incident Tracker that turn on this: Curve Finance Vyper reentrancy and Euler Finance donation attack.
Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.