Logótipo oficial do MASTR MASTR Apoiar o trabalho
Índice
← Início da wiki

Research methods

Audit scope drift: the badge can outlive the reviewed code

Match the report to the software users interact with now.

Research guide · 9 September 2026 · 1 min read

Os artigos de investigação e as referências são publicados em inglês. A navegação está disponível em sete idiomas.

Neste artigo
  1. Pin the reviewed version Record the repository, commit, compiler settings and deployed addresses where available. Check exclusions and assumptions. Distinguish source verification from an audit: showing a relationship between source and deployed bytecode does not establish that the source is free of vulnerabilities.
  2. Follow subsequent changes Look for upgrades, new modules, changed dependencies and configuration changes that affect the report's assumptions. A small diff can alter an important trust boundary. Conversely, a change in website copy does not necessarily mean the audited contract changed.
  3. Explain the remaining coverage State which part of the current system is covered and which part needs further review. Do not describe an old report as fake merely because the software evolved. The concrete issue is whether the current marketing accurately communicates the scope and age of the assessment. Readers need the correspondence, not just the auditor's logo.

An audit report concerns a defined target and scope. This review method asks whether that target still corresponds to the deployed system. A report's existence is useful evidence, but it cannot establish the security of changes that were not examined.

Pin the reviewed version Record the repository, commit, compiler settings and deployed addresses where available. Check exclusions and assumptions. Distinguish source verification from an audit: showing a relationship between source and deployed bytecode does not establish that the source is free of vulnerabilities.

Follow subsequent changes Look for upgrades, new modules, changed dependencies and configuration changes that affect the report's assumptions. A small diff can alter an important trust boundary. Conversely, a change in website copy does not necessarily mean the audited contract changed.

Fontes

Ethereum documentation · verifying

Technical reference checked 9 September 2026. The review questions are editorial analysis, not findings about a named project.

Leituras relacionadas

Tipos de fraude

Audit-badge laundering

An old audit is displayed after code, proxies or administrators have changed.

Tipos de fraude

QR-code substitution

A payment or connection QR code is replaced on a page, document or physical surface.

MASTR

Apoiar a investigação independente

As investigações, as provas originais e os guias são de acesso livre. Os donativos voluntários ajudam a financiar a investigação e a manter disponíveis as ferramentas MASTR.

Abrir carteira