Home/Resources/Audit Checklist
31 Security Checks

Smart Contract Audit Checklist:
31 Checks Before You Deploy

This is the checklist that developers use before spending $5,000–$50,000 on a manual audit. Going into an audit with clean code costs less and gets you a cleaner report.

The first 10 checks are free to read. Enter your email to unlock all 31 items — including the cross-chain bridge and MEV sections that cover Ronin, Wormhole, and Cream Finance attack patterns.

1
Access Control
critical

Every privileged function has an explicit access modifier

onlyOwner, onlyRole, or equivalent. Functions that write state without access control are immediate critical findings.

2
Access Control
critical

Ownership transfer is two-step (propose + accept)

Single-step transferOwnership() lets a typo permanently lock out the owner. Require the new owner to accept before transfer completes.

3
Access Control
critical

No unprotected selfdestruct or delegatecall

Both are irreversible. delegatecall with user-controlled target address is a common exploit vector.

4
Access Control
high

Role separation for admin vs operational actions

The address that can pause the contract should not be the same one that can upgrade it. Separate privilege reduces blast radius.

5
Access Control
critical

Constructor/initializer sets all privileged roles explicitly

Uninitialized roles default to address(0) or empty sets. An attacker who calls initialize() first on a proxy owns the contract.

6
Arithmetic
high

Solidity ≥ 0.8 used, or SafeMath applied on all arithmetic

Solidity 0.8+ reverts on overflow/underflow by default. Anything below needs explicit SafeMath or unchecked blocks must be justified.

7
Arithmetic
medium

Division-before-multiplication patterns eliminated

Solidity integer division truncates. (a / b) * c loses precision. Always multiply before dividing.

8
Arithmetic
critical

No shares/token math that allows first-depositor inflation attacks

Vault/ERC-4626 contracts need virtual shares or minimum deposit to prevent inflation attacks where first depositor manipulates exchange rate.

9
Arithmetic
medium

Reward calculations account for full precision before scaling

Reward per token calculations that truncate early can permanently lose yield. Scale up by 1e18 before dividing.

10
Reentrancy
critical

Checks-Effects-Interactions pattern followed on all external calls

State updates must happen before external calls. The DAO, Cream Finance, and dozens of others violated this. Non-negotiable.

21 More Checks — Free Unlock

Items 11–31 cover Gas/DoS, Upgradability, MEV/sandwich attacks, and Cross-chain bridge vulnerabilities — the patterns behind Ronin ($625M), Wormhole ($320M), and Cream Finance ($130M).

No spam. Unsubscribe anytime.

After the checklist, verify it automatically

This checklist tells you what to look for. SmartContractAuditor.ai scans your actual bytecode and Solidity source against all 31 vulnerability classes in under 60 seconds. Paste your contract and it will flag each item above that it can detect statically — so you go into a manual audit knowing exactly what's already clean.