Smart Contract Audits: Why Your Project Needs One (and How to Prepare)
Over $2 billion was lost to smart contract exploits in 2024, and 2025 didn't slow down. Almost every drained protocol had something in common: either no audit, or an audit that was too rushed, too narrow, or done after the code was already in production. This guide walks through what a proper smart contract audit covers, how much one really costs, and the prep work that turns a 4-week audit into a 1-week audit.
Why an Audit Is Not Optional
The smart contract is the only piece of your stack where a bug doesn't trigger a Sentry alert. It triggers a Twitter thread about your TVL. Once funds are gone, they're gone.
Insurance protocols (Nexus Mutual, Sherlock) require an audit from a recognized firm before they'll cover your protocol. So do most launchpads, exchanges and institutional capital allocators. No audit means no listing, no insurance, no institutional money.
- Pre-mainnet audit is table stakes for any contract holding user funds
- Re-audit is required after any non-trivial post-launch change
- Continuous audits / contests work for high-frequency upgrades
- Most exploits in 2024 hit unaudited contracts or audited code with post-audit changes
What Auditors Actually Check
An audit is not a tool running Slither and a 5-page report. A real audit covers six dimensions:
- Manual code review: Senior auditor reads every line, traces every external call, models every state transition. This is where 80% of high-severity findings come from. Tools find the rest.
- Specification vs implementation: What does the protocol claim to do? Does the code actually do that? Mismatches here are how protocols fail audits even with clean Slither runs.
- Economic / game-theoretic analysis: Can a rational attacker profit by manipulating prices, sandwiching, flash-loaning their way into governance, or exploiting fee curves? Auditors model adversaries.
- Static + symbolic analysis: Slither, Mythril, Aderyn, Halmos, Certora. Tools find a long tail of low-severity issues that humans miss.
- Fuzz + invariant testing: Echidna, Foundry's invariant tests, Medusa. The auditor writes invariants that should hold under any input and tries to break them.
- Deployment + ops review: Is the upgrade path safe? Are admin keys multisig? Are there time-locks? Is monitoring in place? Many incidents are operational, not code-level.
How Much an Audit Costs
Audit pricing in 2026 is broadly tiered by firm reputation and code complexity:
| Firm tier | Lines of code | Cost range | Timeline |
|---|
| Top-tier (Trail of Bits, OpenZeppelin, Spearbit) | 1,000 LOC | $80K – $200K | 4 – 8 weeks |
| Top-tier | 5,000 LOC | $200K – $600K | 8 – 16 weeks |
| Mid-tier (Hacken, Quantstamp, Cyfrin) | 1,000 LOC | $30K – $80K | 3 – 5 weeks |
| Mid-tier | 5,000 LOC | $80K – $250K | 5 – 10 weeks |
| Audit contests (Code4rena, Sherlock) | any size | $30K – $500K prize | 2 – 4 weeks |
| Solo auditors (verified) | 1,000 LOC | $10K – $40K | 2 – 4 weeks |
If your protocol holds more than $5M in TVL on day one, a top-tier audit is the right call. The price difference is small relative to what you'd lose to one critical bug.
How to Prep for an Audit (and Halve the Cost)
Auditors charge by senior-engineer hours. Cleaner code burns fewer hours. Here's the prep that has consistently saved our clients 30-50% on audit fees and timeline:
- Freeze the code 1-2 weeks before audit kickoff. Mid-audit changes restart the clock.
- Achieve 95%+ branch coverage with Foundry tests. Auditors trust you more and skip retesting basic flows.
- Run Slither, Aderyn and Mythril internally first. Fix every High and Medium before submitting.
- Write invariants. Even a few well-formed invariants tell the auditor what guarantees you actually care about.
- Document the threat model: who can call what, what they can do, what they can't. Saves hours of context-gathering.
- Provide a deployment script and a runbook. Operational issues count as findings, so handle them up front.
- Use Solidity 0.8.20+ with custom errors and explicit state machines. Modern code audits faster.
Severity, Findings and What to Fix
Most audit reports use a severity matrix combining likelihood and impact. Here's how to read it:
- Critical / High: Direct loss of funds, governance hijack, full protocol shutdown. Fix every one before mainnet. No exceptions.
- Medium: Conditional loss of funds, broken behavior in edge cases, MEV opportunities. Fix all where the cost-benefit is reasonable. Document accepted risks.
- Low / Informational: Best-practice deviations, gas optimizations, code style. Fix the cheap ones; cherry-pick the rest. Don't let perfectionism delay launch.
- Out of scope: Issues outside the audit perimeter (oracle, governance, off-chain). Track them separately; some will need a follow-up engagement.
A clean audit with zero findings is a red flag. Auditors who find nothing usually didn't look hard enough. Expect 5-15 findings on a non-trivial codebase.
After the Audit: Production Hardening
- Re-test every fix. Audit fixes cause new bugs more often than you'd think.
- Get a second look: even a 1-week sanity check from a different firm catches bugs the first auditor missed.
- Bug bounty on Immunefi from launch. Public bounties of $50K-$1M+ for critical findings on TVL-rich protocols.
- Forta or Tenderly Alerts on mainnet. Get paged when something abnormal happens, not when Twitter notices.
- Plan a re-audit on every major upgrade. New code is unaudited code, regardless of the rest of the contract.
Audits Are Cheap Compared to Exploits
Every protocol that's been drained in 2024-2025 looked correct to its team. The bug was always in the corner none of them examined hard enough. That corner is what auditors are for.
Spend the time and money up front. The marginal cost of a great audit is small compared to the cost of a single critical bug shipped to production.
Frequently asked questions
Can I skip the audit if my protocol is small?
If your protocol holds anyone's funds (yours, your investors', your users'), no. The smallest exploitable contract drains as fast as the biggest. The bar isn't TVL; it's whether funds are at risk.
How long after the audit can I deploy?
1-3 weeks. You need time to fix all High and Medium findings, retest, and ideally have a second pair of eyes on the changes. Deploying the day the audit lands is how regressions hit production.
Are audit contests as good as a private audit?
Different tradeoffs. Contests get more eyeballs and find more findings on average, but with more noise. Private audits are deeper and produce a cleaner report. Many serious protocols do both.
Do I need a re-audit if I change one line?
Depends on the line. Adding a new external function or changing access control? Yes. Renaming a private variable? No. Use judgment, and when in doubt, get a 1-day delta review.
What's a fair price for an audit?
Roughly $400-$800 per hour of senior auditor time, multiplied by a sane estimate of hours. A 1,500-LOC protocol typically takes 80-150 senior hours at a top firm, so $60K-$120K is reasonable.
Related guides