Scope and commit hash
An audit covers specific files at a specific commit. If the deployed contract differs from that commit, the audit does not describe what is live. Check the hash in the report against the deployed, verified source.
Scope exclusions matter too. Reports routinely state that economic design, oracle reliability or dependencies were out of scope, and those are often where the real risk is.
Findings and what happened to them
Count findings by severity and check the resolution status of each. Acknowledged is not fixed — it means the team read it and chose to accept it. A high-severity acknowledged finding is a decision you are now inheriting.
Zero findings on a complex protocol usually means a narrow scope rather than perfect code.
What audits never cover
Governance decisions, admin key behaviour, incentive design, oracle manipulation under extreme conditions, and every contract the audited one interacts with. Also every change made after the report date.
A report is a snapshot of one commit. Protocols ship upgrades, add collateral types and adjust parameters continuously, and none of that is covered by a document written months earlier. The useful question is what has changed since, not whether an audit exists at all.
Most large DeFi losses involved code that had been audited, because the failures were in these categories.
Better signals than an audit badge
Time in production with significant value at stake. An active bug bounty with meaningful payouts. Timelocked governance so changes are visible before they take effect. Multiple independent reviews rather than one.
FBT Swap routes through established public aggregators and does not operate its own lending or pool contracts. Protocol risk belongs to the protocol, and the app names the source of the data it displays.