CASE-09 · 18 min
Audit present, question open
Type of case study: Constructed scenario with invented figures. No real incident, no real protocol.
Scenario
A protocol points to two audit reports and an ongoing bounty for reported vulnerabilities. The contracts are upgradeable. The task is not to assess the reports — it is to determine what they refer to and what the code running today has to do with them.
Data
- Audit report 1
- commit a1b2c3, published 19 months ago
- Audit report 2
- commit d4e5f6, published 7 months ago, scope: the interest module only
- Currently active implementation contract
- live for 5 weeks, no published report covering it
- Upgrade authority
- 3-of-7 multisig
- Delay before an upgrade takes effect
- none
- Bounty program
- active, cap USD 250,000
- Value held in the contract
- USD 310m
Questions
What do the two audit reports evidence about the code running today?
Which of the listed points weighs more for the risk assessment than the missing current report?
Analysis dimensions exercised
Sources
- EVD-2026-0005 — Review of Accounting Studies (Springer): Decentralized Finance (DeFi) assurance: early evidence
- EVD-2026-0004 — Annual Review of Financial Economics: Smart Contracts and Decentralized Finance
Institutional perspectives
Bank · Insurance · Asset management