This is the checklist that developers use before spending $5,000–$50,000 on a manual audit. Going into an audit with clean code costs less and gets you a cleaner report.
The first 10 checks are free to read. Enter your email to unlock all 31 items — including the cross-chain bridge and MEV sections that cover Ronin, Wormhole, and Cream Finance attack patterns.
Every privileged function has an explicit access modifier
onlyOwner, onlyRole, or equivalent. Functions that write state without access control are immediate critical findings.
Ownership transfer is two-step (propose + accept)
Single-step transferOwnership() lets a typo permanently lock out the owner. Require the new owner to accept before transfer completes.
No unprotected selfdestruct or delegatecall
Both are irreversible. delegatecall with user-controlled target address is a common exploit vector.
Role separation for admin vs operational actions
The address that can pause the contract should not be the same one that can upgrade it. Separate privilege reduces blast radius.
Constructor/initializer sets all privileged roles explicitly
Uninitialized roles default to address(0) or empty sets. An attacker who calls initialize() first on a proxy owns the contract.
Solidity ≥ 0.8 used, or SafeMath applied on all arithmetic
Solidity 0.8+ reverts on overflow/underflow by default. Anything below needs explicit SafeMath or unchecked blocks must be justified.
Division-before-multiplication patterns eliminated
Solidity integer division truncates. (a / b) * c loses precision. Always multiply before dividing.
No shares/token math that allows first-depositor inflation attacks
Vault/ERC-4626 contracts need virtual shares or minimum deposit to prevent inflation attacks where first depositor manipulates exchange rate.
Reward calculations account for full precision before scaling
Reward per token calculations that truncate early can permanently lose yield. Scale up by 1e18 before dividing.
Checks-Effects-Interactions pattern followed on all external calls
State updates must happen before external calls. The DAO, Cream Finance, and dozens of others violated this. Non-negotiable.
Items 11–31 cover Gas/DoS, Upgradability, MEV/sandwich attacks, and Cross-chain bridge vulnerabilities — the patterns behind Ronin ($625M), Wormhole ($320M), and Cream Finance ($130M).
No spam. Unsubscribe anytime.
This checklist tells you what to look for. SmartContractAuditor.ai scans your actual bytecode and Solidity source against all 31 vulnerability classes in under 60 seconds. Paste your contract and it will flag each item above that it can detect statically — so you go into a manual audit knowing exactly what's already clean.