Web3/Blockchain

Smart Contract Audit Checklist

Score a smart contract against the failure classes that actually cause losses, covering access control, reentrancy ordering, rounding direction, oracle manipulation and process.

Last reviewed by the Radiatus Cloud team

Results appear here.

Need this done properly for your business?

Radiatus delivers secure cloud, DevOps & compliance engineering.

Book a free consult

Access control causes more losses than clever exploits

The exploits that get written up are usually intricate, and the ones that take the money are usually a function nobody protected. An unprotected initialiser on a proxy, an admin function missing its modifier, a withdrawal path reachable by anyone: these are simple, findable and have repeatedly cost entire protocols. They persist because they are boring to look for and because reviewers gravitate toward the interesting parts of a codebase, which are rarely where the missing modifier is.

Rounding direction is a whole class of exploit that never looks like a bug

When a calculation rounds in the user's favour, no single transaction is wrong. Repeat it ten thousand times and the protocol has been drained by an amount nobody can point to a bug for. Every division in a contract that handles value has a correct direction, and getting it right is a matter of deciding deliberately rather than accepting whatever the compiler does. This is also why an auditor asks about rounding early: the answer reveals whether that decision was ever made.

An AMM spot price is not an oracle

A spot price read from a pool can be moved arbitrarily inside a single transaction using borrowed capital that is repaid in the same transaction, so any contract pricing off one can be made to see whatever the attacker chooses. A large share of all DeFi losses by value trace to this single pattern. The defence is not to sanity-check the spot price but to stop using it: a time-weighted price, a dedicated feed, or several sources that must agree.

Related tools

Frequently Asked Questions

What causes the most losses?

Access control failures, particularly unprotected initialisers and admin functions missing a modifier. They are simple and findable, and they persist because reviewers gravitate toward the interesting parts of a codebase.

Is a reentrancy guard enough?

It is defence in depth on top of correct ordering, not a substitute for it. Writing state before making external calls makes reentrancy impossible rather than merely guarded, and read-only reentrancy defeats a guard anyway.

Why does rounding direction matter so much?

Because a calculation rounding in the user’s favour is not wrong in any single transaction and drains the protocol over ten thousand of them. There is no bug to point at afterwards.

Can I use a pool price as an oracle?

No. It can be moved arbitrarily inside one transaction with borrowed capital repaid in the same transaction, and a large share of all DeFi losses by value trace to exactly that.

Does an audit make a contract safe?

No. It reduces the probability of a known class of error surviving. Audited protocols are exploited regularly, which is why monitoring, a rehearsed pause and a funded bounty are on this list alongside the audit.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Tick what is in place to score the contract.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.