# Smart contract audit

> An independent review of contract code before it goes live, looking for the ways it can be drained, locked or manipulated.

Because deployment is usually final and the code is public to everyone including the people who want your funds, review happens before launch or not usefully at all. Auditors look for the recurring shapes — reentrancy, arithmetic that wraps, access control that is not where it should be, oracle prices that can be moved, logic that assumes an ordering the mempool does not guarantee — and then for the mistakes specific to what this contract is trying to do.

An audit is a snapshot, not a certificate. It covers a specific commit under specific assumptions, and a change made after it is unreviewed code regardless of what the report says. Treating the report as a permanent badge is a misreading that has preceded a number of expensive incidents.

## Related terms

- https://dfieldsolutions.com/en/glossary/smart-contract.md
- https://dfieldsolutions.com/en/glossary/solidity.md
- https://dfieldsolutions.com/en/glossary/security-audit.md
- https://dfieldsolutions.com/en/glossary/penetration-test.md

---

Source: https://dfieldsolutions.com/en/glossary/smart-contract-audit
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
