An audit is only useful if it applies to the code you're using
Audits review source code at one point in time. People and platforms interact with the bytecode that is live on the blockchain. Today, nobody checks that the two match.
Around $3.4 billion was stolen through crypto hacks and exploits in 2025. Wallets, exchanges and insurers deserve better evidence than a PDF and a badge.
The wrong code can carry the audit
A project can deploy code that differs from what the auditors reviewed, or cite an audit of a different contract, and still display the badge.
Audits go out of date silently
Upgradeable contracts can swap their logic behind the same address. The old report keeps vouching for code nobody has reviewed.
“Fixed” is only a claim
When a report says a critical issue was resolved, that is simply what someone has declared. No one confirms it in the live contract.
What changes with Auditrail
| Question | Today | With Auditrail |
|---|---|---|
| Which code was audited? | A PDF names a repository, sometimes a commit | The exact commit, rebuilt and fingerprinted |
| Does the live contract match? | Not checked | Checked function by function |
| What happens after an upgrade? | The badge stays up | Status updates automatically, wherever it's shown |
| Were the issues really fixed? | Declared by the project | Confirmed in the deployed code |
| Who stands behind the report? | Anyone can post a PDF | A verified audit firm, with a permanent record |
How it works
Every audit becomes a record tied to specific code, and that record is checked against the blockchain for as long as the contract is live.
The firm publishes
A verified audit firm publishes its report with the exact commit it reviewed and every finding. Publishing is free.
We fingerprint the code
We rebuild the audited code and store a fingerprint, ignoring values that are expected to change at deployment.
We match it on-chain
The fingerprint is compared with the deployed contract, and each finding is traced to its function to confirm the fix.
We keep watching
When a contract is upgraded, we check the new code straight away and update its status everywhere it appears.
What we provide
Auditrail data plugs into the tools people already use to decide whether a contract is safe to touch.
Wallets and explorers
- An API that returns audit coverage and open issues for any address
- A risk check before users sign a transaction
- A security label that updates itself and warns if copied onto another site
Exchanges and custodians
- Time-stamped evidence packs for listing and custody reviews
- Alerts when a listed token's contract is upgraded
- An enterprise API with guaranteed uptime
Audit firms
- Free, verified publishing under your firm's name
- Proof that your recommended fixes were deployed
- Protection against reports being attached to code you didn't review
Insurers and researchers
- A data feed of audit coverage, open findings and past exploits
- A historical dataset for pricing and risk modelling
Why we're starting in the UK
The UK is bringing cryptoasset firms under full FCA authorisation. Exchanges, custodians and wallet providers will need to show how they assessed the tokens they list and the assets they hold. London is also home to the specialist insurers pricing this risk.
| 30 Sep 2026 | FCA opens applications from cryptoasset firms |
| 25 Oct 2027 | The new regime is scheduled to come into force |
| Now | UK firms serving EU customers already work under the EU's MiCA rules |
stolen through crypto hacks and exploits in 2025
Chainalysisof UK adults hold cryptoassets, with more holding larger amounts
FCA research, 2025the year FCA rules for cryptoasset firms take effect
Financial Conduct AuthorityQuestions
Auditrail is neutral by design. We don't compete with the firms that publish with us, and we don't tell people what to think.
Does Auditrail audit smart contracts?
No. We don't audit and we never will, so we don't compete with the firms that publish with us.
Do you give projects a safety score?
No. We report facts that can be checked: which code was audited, whether it matches what's deployed, and whether reported issues were fixed.
Is there a token?
No. Auditrail is paid for by the organisations that use the data.
What does it cost audit firms?
Nothing. Verified audit firms publish for free.
Where are reports stored?
Each report is stored on IPFS and tied to the firm's verified account, so it can't be quietly edited after publication.