An Audit Report Is a Snapshot, Not a Warranty
The badge on the landing page tells you a firm reviewed a commit hash. It does not tell you what shipped.
In nearly every incident I have covered, an audit existed. In most of them the audit was accurate about the code it examined, and the code that was exploited was not that code.
Reviews are scoped to a commit. Between that commit and the exploit sit upgrades, parameter changes, new integrations and privileged operations, none of which the report covers and all of which routinely introduce the failure.
Teams know this. Users, reading a logo on a landing page, generally do not, and the incentive to clarify is weak because ambiguity is commercially useful.
A modest fix would help: publish the reviewed commit hash next to the badge, mark it stale when the deployed bytecode diverges, and say plainly which contracts were out of scope. Firms that do this already exist. They should not be the exception.
This column reflects the author's views and is labelled Opinion under MyBunnyFarm's editorial policy.
- security
- audits
- opinion
- smart contracts
About the author
Naomi Feldstein — Naomi Feldstein covers security: bridge exploits, custody failures, laundering typologies and the slow work of tracing stolen funds. She spent five years in incident response before turning to reporting and verifies every attribution against on-chain evidence.
Security & Forensics Reporter · Tel Aviv, Israel · More from Naomi Feldstein
Corrections to this report: corrections desk. Nothing in this article is investment advice.
