Skip to main content

Audit Quality

Analyzes the frequency and scope of completed smart contract audits, the credibility of the auditors, and the size and structure of any bug bounty programs. Contract complexity influences the weight of the metric.

Weighted scoring combines audit quality, contract maturity, audit quantity, and bug bounty design. Audit quality dominates because what matters is whether the right attack surface was reviewed and whether findings were fixed in the currently deployed code, not how many reviews were done. Bug bounty programs are evaluated for size and structure, with publicly known programs scaled to TVL signalling mature post-launch security posture.

TierReasoningEvidence
Formal verification on critical paths and multiple top-rated auditsCombines methodological diversity (manual review, symbolic analysis, formal verification) with proof of invariant preservation — asset conservation, solvency, mint/burn correctness — that line-by-line review systematically misses. Recency matches the deployed bytecode and remediation is verified.Halborn's Top 100 DeFi Hacks (2016–2023) found audited protocols accounted for only 14.3% of value lost. A British Accounting Review study of 316 large DeFi protocols (2024) confirmed higher-quality auditor coverage correlates with higher TVL. Formal verification has been applied at MakerDAO core, Compound v2, and Tornado Cash.
Multiple standard audits with established bug bountySeveral independent reviewers cover the core attack surface with reasonable scope and remediation, supplemented by a standing post-launch incentive for external researchers to disclose residual vulnerabilities. Falls short of the top tier where methodological diversity or formal proof of economic invariants is absent.Modal population across mainstream DeFi protocols, consistent with the bulk of the CertiK and Halborn datasets. Examples: Aave V3, Compound V3, major DEX protocols. Bug bounty programs scaled to TVL (Immunefi listings of $1M–$10M+) signal mature post-launch security posture.
Single audit or narrow coverageOne review or narrowly-scoped coverage leaves entire vulnerability classes — input validation, accounting paths, upgrade safety, integration surfaces — un-tested, with no diverse second opinion to catch what the first methodology systematically misses.Wormhole had approximately 29 audits at the time of its $326M exploit (February 2022); Euler was reviewed six times before its $197M hack (March 2023); Beanstalk's auditor explicitly noted the exploited code was never in scope. Audit count without scope coverage carries no predictive value.
Unaudited or newly deployedNo independent third party has examined the deployed bytecode for known vulnerability classes; the protocol relies entirely on internal review.CertiK Hack3d 2024 identified $2.36B lost across 760 incidents, with unaudited and newly deployed protocols heavily over-represented in the loss distribution. PancakeBunny (May 2021, $45M), Cashio (March 2022, $52M), and dozens of smaller pre-launch exploits anchor this tier.