Skip to main content

Command Palette

Search for a command to run...

Auditing a Smart Contract

Updated
•2 min read•View as Markdown
Auditing a Smart Contract
A

Golang Developer and Blockchain certified professional

Smart contract Audit is a process to find security flaws and vulnerabilities before deploying the code

The auditing process follows a strict methodology. For this reason, smart contract audits take time and require resources

  1. Source Code Lock-down
  2. Project Familiarization Phase
  3. Preliminary Code Review

2nd stage

  1. Static Code Analysis
  2. Code Quality Analysis
  3. Known Vulnerability Analysis(A line by line code analysis is performed against a checklist of known vulnerabilities)
  4. Functionality Analysis
  5. Live Testing
  6. Gas Usage
  7. First draft of the report with errors found
  8. Audit Report

Audit performed in two ways ● Manual Code Analysis ● Automatic Code Analysis

When auditing smart contracts the below are the basic checklist to be • Basic Coding Bugs: We first statically analyze given smart contracts with our proprietary static code analyzer for known coding bugs, and then manually verify (reject or confirm) all the issues found by our tool

  • Constructor Mismatch
  • Ownership takeover
  • Overflows and Underflows
  • Reentrancy
  • Revert DoS
  • Unauthorized Self Destruct

SWC registry is a very handy resource of known vulnerabilities - https://swcregistry.io/

The goals of the SWC scheme are as follows:

  1. Provide a straightforward way to classify weaknesses in smart contract systems.
  2. Provide a straightforward way to identify the weakness(es) that lead to a vulnerability in a smart contract system.
  3. Define a common language for describing weaknesses in smart contract systems' architecture, design and code.
  4. Train and increase the performance of smart contract security analysis tools.

Semantic Consistency Checks: We then manually check the logic of implemented smart contracts and compare with the description in the white paper.

After the security and functionality of the smart contracts have been confirmed, we look at their efficiency. Gas usage is analyzed, first through an automated gas estimation

Follow the below quality checklist to ensure a smooth Audit

Write clean code with a consistent code style Use standard libraries where possible Include a test suite (ideally 100% code coverage) Document the functions of your public API (at least) Document your protocol and release process If creating a token, document the creation and distribution process Include end-user documentation where relevant

The exact cost of an audit depends on the number of smart contracts to be checked. Typically, an audit will run into thousands of dollars. A particular large project can easily cost over $10,000. The audit company running your audit and its reputation will also affect how much you pay.

More from this blog

Ashok V

37 posts

Go beyond limits with our Golang blog with Tips, Tricks, and Insights