Last month a project announced a $100 million raise. The same thread announced a "completed security audit." I opened the PDF. Sixteen pages. The findings table contained a single row: "No critical issues identified." The scope section read, in full, "smart contracts." The methodology section was blank. No commit hash, no test coverage figure, no line-item inventory of what had actually been read. Two thousand replies congratulated the team. Not one asked which functions were in scope. I read the reverts before the headlines — and here there were no reverts to read, because there was no code attached to the claim.
This is the artifact the bull market manufactures. Not a vulnerability. A vacuum dressed as assurance.
I have been tracing contract logic since the winter of 2017, when I spent fourteen nights manually walking the liquidity pool mechanics of the 0x protocol v2 whitepaper and its preliminary testnet contracts. I found an integer overflow in the exchange function that would have let an attacker drain liquidity with trivial capital. I submitted the proof-of-concept through a GitHub issue rather than chasing a bounty. The point was never the payout. The point was that a claim without a traceable proof is not a claim — it is a wish.
The industry has since industrialized the wish. Security review has become a line item in the fundraising narrative, procured the way a company buys a logo for its homepage. The economic incentive is inverted. A vendor who writes "no critical issues" gets rehired. A vendor who writes "your governance module is exploitable" gets argued with, then quietly dropped from the next engagement. Code does not lie, but incentives do. When the buyer wants a clean report and the seller is paid to produce one, the equilibrium is not security. The equilibrium is a sixteen-page document that certifies nothing.
So let me describe what a real audit contains, because the absence is the finding. A legitimate review begins with a scope contract: exact repository, exact commit hash, exact set of deployed addresses. It states a threat model — who the adversary is, what capital they control, what privileges they hold. It enumerates findings with severity, each backed by a reproducible proof-of-concept, a remediation recommendation, and a retest confirming the fix. It reports coverage: which branches were executed, which invariants were tested. Strip any one of those and you no longer have an audit. You have a brochure.
The brochure in question was raised on the promise of "AI-agent autonomous execution." I spent part of 2026 auditing three platforms in exactly that category. In one, the payment routing logic contained a reentrancy path: if the external AI model returned a delayed response, the agent's settlement callback could be invoked again before state finalized. An agent could drain funds by simply being slow. The team's own documentation called the design "fully autonomous." Nothing autonomous about a reentrancy window. The automation had replaced the human operator but inherited none of the human's caution, and the audit that should have caught it had reviewed "smart contracts."
This pattern is older than AI. In 2021 I simulated the Compound governance voting-delay mechanics after a string of failed votes and demonstrated how a coordinated actor could manipulate proposal timing to slip a change past community scrutiny. The wider market was watching TVL curves. The exploit lived in a parameter nobody had modeled. Decentralized governance, in that instance, was a facade stretched over a centralized operational risk — and the facade was load-bearing only until someone leaned on it.
Oracle feeds carry the same latent debt. I spent three weeks in May 2022 reconstructing Anchor's price feed and simulating the feedback loop between stablecoin redemption and LUNA mint-burn. The peg did not fail because of "bad actors." It failed because the model had a structural threshold, and the model crossed it. I published the numbers, not the narrative. The logic held until the liquidity dried up — and the liquidity was always going to dry up, because the incentives guaranteed it.
Here is what the bulls got right, and I will not pretend otherwise. Formal verification is not theater. Some review firms produce rigorous, adversarial work, and a handful of protocols genuinely ship hardened code. The existence of the empty brochure does not invalidate the discipline. What it invalidates is the signal — the assumption that a PDF attached to a raise means someone checked. The market is not wrong to want assurance. It is wrong to accept a document that never names what it read.
The fix is not more audits. It is verifiable audits. A scope without a commit hash is unfalsifiable. A findings list without proof-of-concept is unverifiable. The exploit was in the trust, not the contract — and the trust was extended to a sixteen-page document that declined to say which sixteen lines it examined.

So when the next $100 million raise lands with its clean report, open the PDF. Find the commit hash. Find the threat model. If they are missing, you have your answer, and it is the only finding that matters. Silence is just uncompiled potential energy — and this market has been very, very quiet. Entropy always wins if you stop watching.