Because deployment is usually final and the code is public to everyone including the people who want your funds, review happens before launch or not usefully at all. Auditors look for the recurring shapes — reentrancy, arithmetic that wraps, access control that is not where it should be, oracle prices that can be moved, logic that assumes an ordering the mempool does not guarantee — and then for the mistakes specific to what this contract is trying to do.
An audit is a snapshot, not a certificate. It covers a specific commit under specific assumptions, and a change made after it is unreviewed code regardless of what the report says. Treating the report as a permanent badge is a misreading that has preceded a number of expensive incidents.
Related terms
Smart contract
A program deployed to a blockchain that runs exactly as written, that anyone can call, and that usually cannot be changed afterwards.
Solidity
The main language for writing smart contracts on Ethereum and the other chains that run the same virtual machine.
Security audit
A systematic review of a system against a standard or a set of criteria, aiming for coverage rather than for a way in.
Penetration test
An authorised, scoped attempt to break into a system, done to find out what an attacker could actually achieve.
The bench this belongs to
BlockchainSolidity on Ethereum, Polygon, Base and Arbitrum. Anchor programs on Solana. Written with tests first, because a redeploy is not a hotfix once value is on the line.
