What an audit is worth

An audit is a code review with a method and a report. Treating it as a seal of safety is the most common mistake in this market, and the report usually says so itself.

The short version

  • An audit searches for known vulnerability classes: reentrancy, overflow, bad access control, broken arithmetic.
  • Findings are graded by severity, and a report is only meaningful if you read what was found and what the team fixed.
  • An audit of the code says nothing about whether the economics behind the code can work.
  • A badge is a marketing asset; the report is the document, and the two often tell different stories.
  • Renounced ownership removes the admin risk and removes the ability to patch, in one move.

What the work consists of

An auditor reads the source, runs tools against it and tries to make it misbehave: can a function be called in an order the author did not expect, can a value overflow, can an address that should not be able to withdraw do so anyway. The output is a list of findings with severities and, usually, the team’s response to each.

That is valuable and bounded. It raises the cost of a straightforward exploit. It cannot prove the absence of bugs, and it does not pretend to: read the disclaimer in any report and it says exactly this.

The question audits usually skip

Code correctness and business viability are different subjects. A contract can be flawless at doing something unsustainable, paying a fixed rate it cannot fund is not a bug, it is a design the code implements perfectly.

Some auditors do comment on the model anyway, and when they do it is the most important paragraph in the document. It is also the paragraph least likely to appear on the landing page that links to the report.

How to read one in five minutes

Open the report rather than the badge. Find the findings table, read every high and critical entry, and check what the response was: fixed, acknowledged or disputed. Then look at the scope section to see which contracts and which commit were actually reviewed.

Finally check the date. An audit covers a version of the code at a moment in time, and a contract deployed afterwards may not be the one that was audited.

What this changes about reading TurboLoop

  • Three audit documents exist, and two of them are worth opening rather than counting.
  • SolidityScan scored the protocol 99.99 with no critical, high, medium or low findings: a code result, not an economic one.
  • HazeCrypto did reach the economics: it records a high-severity finding on the ROI model and states that dividends are paid from other users’ deposits.