An audit checks named code at a named commit against a defined threat model. It says nothing about the deployment, the keys, the governance, or the front end around that code — and the industry's own loss data cannot agree on how big that gap is. The post What a smart contract au...