Audit reports, checked against the code that is actually deployed.

When a smart contract says it has been audited, most people take that on trust. Auditrail links each audit to the exact code that was reviewed, compares it with the contract running on the blockchain, and keeps checking after every upgrade.

0x7a3f91d04c2e…8b55c91eEthereum mainnet · lending pool
Audit coverage
Fully coveredLive code matches the audited commit
38 of 38 functions match audited codeEach square is one function
Audited byVerified audit firm
Commit revieweda1c9e04
Implementation0x41be…08d2
Findings
  • CriticalReentrancy in withdraw()Fix confirmed in deployed code
  • HighOracle price not checked for stalenessFix confirmed in deployed code
  • MediumNo event emitted on fee changeFix confirmed in deployed code

Example record with illustrative data. Switch to “After an upgrade” to see what happens when the code behind an address changes.

An audit is only useful if it applies to the code you're using

Audits review source code at one point in time. People and platforms interact with the bytecode that is live on the blockchain. Today, nobody checks that the two match.

Around $3.4 billion was stolen through crypto hacks and exploits in 2025. Wallets, exchanges and insurers deserve better evidence than a PDF and a badge.

The wrong code can carry the audit

A project can deploy code that differs from what the auditors reviewed, or cite an audit of a different contract, and still display the badge.

Audits go out of date silently

Upgradeable contracts can swap their logic behind the same address. The old report keeps vouching for code nobody has reviewed.

“Fixed” is only a claim

When a report says a critical issue was resolved, that is simply what someone has declared. No one confirms it in the live contract.

What changes with Auditrail

QuestionTodayWith Auditrail
Which code was audited?A PDF names a repository, sometimes a commitThe exact commit, rebuilt and fingerprinted
Does the live contract match?Not checkedChecked function by function
What happens after an upgrade?The badge stays upStatus updates automatically, wherever it's shown
Were the issues really fixed?Declared by the projectConfirmed in the deployed code
Who stands behind the report?Anyone can post a PDFA verified audit firm, with a permanent record

How it works

Every audit becomes a record tied to specific code, and that record is checked against the blockchain for as long as the contract is live.

Audit report Published by a verified firm commit a1c9e04 · 3 findings Code fingerprint Rebuilt with the same settings 38 functions Live contract Matched function by function Fully covered rebuild compare upgrade detected: re-check the new code

The firm publishes

A verified audit firm publishes its report with the exact commit it reviewed and every finding. Publishing is free.

We fingerprint the code

We rebuild the audited code and store a fingerprint, ignoring values that are expected to change at deployment.

We match it on-chain

The fingerprint is compared with the deployed contract, and each finding is traced to its function to confirm the fix.

We keep watching

When a contract is upgraded, we check the new code straight away and update its status everywhere it appears.

What we provide

Auditrail data plugs into the tools people already use to decide whether a contract is safe to touch.

Wallets and explorers

  • An API that returns audit coverage and open issues for any address
  • A risk check before users sign a transaction
  • A security label that updates itself and warns if copied onto another site

Exchanges and custodians

  • Time-stamped evidence packs for listing and custody reviews
  • Alerts when a listed token's contract is upgraded
  • An enterprise API with guaranteed uptime

Audit firms

  • Free, verified publishing under your firm's name
  • Proof that your recommended fixes were deployed
  • Protection against reports being attached to code you didn't review

Insurers and researchers

  • A data feed of audit coverage, open findings and past exploits
  • A historical dataset for pricing and risk modelling

Why we're starting in the UK

The UK is bringing cryptoasset firms under full FCA authorisation. Exchanges, custodians and wallet providers will need to show how they assessed the tokens they list and the assets they hold. London is also home to the specialist insurers pricing this risk.

30 Sep 2026FCA opens applications from cryptoasset firms
25 Oct 2027The new regime is scheduled to come into force
NowUK firms serving EU customers already work under the EU's MiCA rules
$3.4bn

stolen through crypto hacks and exploits in 2025

Chainalysis
8%

of UK adults hold cryptoassets, with more holding larger amounts

FCA research, 2025
2027

the year FCA rules for cryptoasset firms take effect

Financial Conduct Authority

Questions

Auditrail is neutral by design. We don't compete with the firms that publish with us, and we don't tell people what to think.

Does Auditrail audit smart contracts?

No. We don't audit and we never will, so we don't compete with the firms that publish with us.

Do you give projects a safety score?

No. We report facts that can be checked: which code was audited, whether it matches what's deployed, and whether reported issues were fixed.

Is there a token?

No. Auditrail is paid for by the organisations that use the data.

What does it cost audit firms?

Nothing. Verified audit firms publish for free.

Where are reports stored?

Each report is stored on IPFS and tied to the firm's verified account, so it can't be quietly edited after publication.

Become a founding partner

We're launching in the UK and EU with 10 to 15 audit firms and 3 to 5 wallets, explorers, exchanges or custodians. Founding partners help shape the data standard, get early access and are listed as founding members of the registry.