Curriculum·G203 Reading Audit Reports·about 30 min

What an audit is, and what Merlin's did not say

By the end of this lesson you can

  • State what a smart-contract audit checks and the two very different questions it can answer
  • Explain how Merlin DEX passed a high-scoring audit and was drained by its own developers days later
  • Compute why a security score says nothing about who can take the funds if the code has no bug
  • Read an audit's own statement of what it did and did not examine before trusting its conclusion

Graduate · enrolled learners

This lesson opens with Merlin DEX, 26 April 2023.

What happened
Merlin, a decentralized exchange on zkSync, said its pools would open only after CertiK finished auditing its contracts. The 14 April CertiK report found no critical issues and gave the protocol a security score of 90. Less than a day after the public sale went live, about 1.8 million dollars was drained from the pools by a party holding the private keys to Merlin's own contracts. CertiK later described it as a suspected rogue-developer rug, accepted partial responsibility for not stressing the centralization risk to users, said it would emphasize that risk in future audit summaries, and put up a compensation plan of about 2 million dollars. The code had no critical bug and the people who deployed it could take everything, and both statements were true at once.
The decision point
Merlin's users read a number, a security score of 90, and heard it as safe. The audit had answered a narrow question well: does the code contain exploitable bugs. It had barely touched a different question that decided their money: can the people who control the contracts take the funds. Those are two separate audits, and a clean answer to the first says nothing about the second. Reading an audit is knowing which of the two questions it answered, how thoroughly, and which it left open. A high score on code correctness sitting next to an unlimited developer key is not a contradiction; it is two facts about two different risks, and a user who reads only the score sees one of them.
Recorded loss
$1,800,000

What you will be able to answer

  • What are the two questions an audit can answer?
  • How was Merlin drained despite a 90 score?
  • Why does a high score not cover developer-key risk?
  • What to read first in an audit?

Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.

It is free. We do not sell the list and there is nothing to buy at the end of it.

Terms used here

Sources and review

Confidence high·Volatility medium·Reviewed 2026-09-14·Owner unassigned

Contested

Merlin was described by CertiK as a suspected rogue-developer rug; the exact identities and intent were not fully established. The load-bearing facts are the high audit score and the key-based drain days later.

J306 owns protocol risk rating from the user's due-diligence angle. This lesson uses Merlin to teach what an audit does and does not answer. Keep the split.