Logo MASTR ufficiale MASTR Sostieni il lavoro
Indice
← Home della wiki

Research methods

Audit scope drift: the badge can outlive the reviewed code

Match the report to the software users interact with now.

Research guide · 9 September 2026 · 1 min read

Gli articoli di ricerca e le schede sono pubblicati in inglese. La navigazione è disponibile in sette lingue.

In questo articolo
  1. Pin the reviewed version Record the repository, commit, compiler settings and deployed addresses where available. Check exclusions and assumptions. Distinguish source verification from an audit: showing a relationship between source and deployed bytecode does not establish that the source is free of vulnerabilities.
  2. Follow subsequent changes Look for upgrades, new modules, changed dependencies and configuration changes that affect the report's assumptions. A small diff can alter an important trust boundary. Conversely, a change in website copy does not necessarily mean the audited contract changed.
  3. Explain the remaining coverage State which part of the current system is covered and which part needs further review. Do not describe an old report as fake merely because the software evolved. The concrete issue is whether the current marketing accurately communicates the scope and age of the assessment. Readers need the correspondence, not just the auditor's logo.

An audit report concerns a defined target and scope. This review method asks whether that target still corresponds to the deployed system. A report's existence is useful evidence, but it cannot establish the security of changes that were not examined.

Pin the reviewed version Record the repository, commit, compiler settings and deployed addresses where available. Check exclusions and assumptions. Distinguish source verification from an audit: showing a relationship between source and deployed bytecode does not establish that the source is free of vulnerabilities.

Follow subsequent changes Look for upgrades, new modules, changed dependencies and configuration changes that affect the report's assumptions. A small diff can alter an important trust boundary. Conversely, a change in website copy does not necessarily mean the audited contract changed.

Fonti

Ethereum documentation · verifying

Technical reference checked 9 September 2026. The review questions are editorial analysis, not findings about a named project.

Letture correlate

Tipi di truffa

Audit-badge laundering

An old audit is displayed after code, proxies or administrators have changed.

Tipi di truffa

QR-code substitution

A payment or connection QR code is replaced on a page, document or physical surface.

MASTR

Sostieni la ricerca indipendente

Le indagini, le prove originali e le guide sono accessibili gratuitamente. Le donazioni volontarie contribuiscono a finanziare la ricerca e a mantenere disponibili gli strumenti MASTR.

Apri wallet