Smart Contract Audit Checklist
Score a smart contract against the failure classes that actually cause losses, covering access control, reentrancy ordering, rounding direction, oracle manipulation and process.
Last reviewed by the Radiatus Cloud team
Need this done properly for your business?
Radiatus delivers secure cloud, DevOps & compliance engineering.
Access control causes more losses than clever exploits
The exploits that get written up are usually intricate, and the ones that take the money are usually a function nobody protected. An unprotected initialiser on a proxy, an admin function missing its modifier, a withdrawal path reachable by anyone: these are simple, findable and have repeatedly cost entire protocols. They persist because they are boring to look for and because reviewers gravitate toward the interesting parts of a codebase, which are rarely where the missing modifier is.
Rounding direction is a whole class of exploit that never looks like a bug
When a calculation rounds in the user's favour, no single transaction is wrong. Repeat it ten thousand times and the protocol has been drained by an amount nobody can point to a bug for. Every division in a contract that handles value has a correct direction, and getting it right is a matter of deciding deliberately rather than accepting whatever the compiler does. This is also why an auditor asks about rounding early: the answer reveals whether that decision was ever made.
An AMM spot price is not an oracle
A spot price read from a pool can be moved arbitrarily inside a single transaction using borrowed capital that is repaid in the same transaction, so any contract pricing off one can be made to see whatever the attacker chooses. A large share of all DeFi losses by value trace to this single pattern. The defence is not to sanity-check the spot price but to stop using it: a time-weighted price, a dedicated feed, or several sources that must agree.
Related tools
- Ethereum Unit Converter — Convert between Wei, Gwei, and Ether units.
- Gas Fee Calculator — Calculate transaction costs based on gas price and limit.
- IPFS CID Generator — Generate IPFS Content Identifiers (CID) from text or files.
- Wallet Address Validator — Validate Ethereum and Bitcoin wallet addresses.
Frequently Asked Questions
What causes the most losses?
Access control failures, particularly unprotected initialisers and admin functions missing a modifier. They are simple and findable, and they persist because reviewers gravitate toward the interesting parts of a codebase.
Is a reentrancy guard enough?
It is defence in depth on top of correct ordering, not a substitute for it. Writing state before making external calls makes reentrancy impossible rather than merely guarded, and read-only reentrancy defeats a guard anyway.
Why does rounding direction matter so much?
Because a calculation rounding in the user’s favour is not wrong in any single transaction and drains the protocol over ten thousand of them. There is no bug to point at afterwards.
Can I use a pool price as an oracle?
No. It can be moved arbitrarily inside one transaction with borrowed capital repaid in the same transaction, and a large share of all DeFi losses by value trace to exactly that.
Does an audit make a contract safe?
No. It reduces the probability of a known class of error surviving. Audited protocols are exploited regularly, which is why monitoring, a rehearsed pause and a funded bounty are on this list alongside the audit.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Tick what is in place to score the contract.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.