Trust Protocols Entry #0890 Classified Declassified

Why a security page lists what was checked, never what was skipped

A security page enumerates everything reviewed and passed, but never the scope it excluded, so the reader sees the tested surface and never the untested one.

No visual record attached The written record below is complete.
Plate 790 — The exhaustive list that never named the module it left out

Intuition test — answer before you read on

Why does listing all security checks still mislead about a system’s safety?

A protocol’s security page listed, in detail, the components audited, the tests run and the standards met. It read as exhaustive. What it never stated was the scope boundary — which contracts, functions and assumptions had been excluded from review. The exploit, when it came, lived in an unaudited module that the page had simply not mentioned. Nothing on the page was false. The manipulation was the shape of the disclosure: all of the checked surface shown, none of the unchecked surface named.

What everyone sees

A reader sees a long, specific list of security measures and infers completeness: this much detail must mean the whole system was covered. Enumeration reads as thoroughness. The reader treats the list as the full map of the system’s security, assuming that anything important would appear, and so concludes that what is not flagged as a risk has been checked and cleared.

What is actually happening

Every audit has a scope, and the excluded portion is as decision-relevant as the included one, yet disclosure norms let projects publish only the positive space. Security researchers stress that a report’s scope statement — what was not examined and why — is essential to interpreting it, and that its omission is a common way to imply broader coverage than was purchased. A list of what passed, without the boundary of what was never tested, systematically overstates assurance.

Why it stays hidden

The hidden mechanism is disclosure by positive space only. By listing the tested surface and omitting the scope boundary, the page lets the reader’s assumption of completeness fill the gap. The untested region leaves no mark, so it is never weighed. The truth of every listed item guarantees nothing about the unlisted whole, and the absence of the exclusions is precisely what makes the coverage look total.

A security page shows the tested surface and hides its edge. What was skipped leaves no line to read, so completeness is assumed.

A security page shows the tested surface and hides its edge. What was skipped leaves no line to read, so completeness is assumed.

The hidden part — entry #0890

Collect this card

A security page shows the tested surface and hides its edge. What was skipped leaves no line to read, so completeness is assumed.

0 / 10,000 collected

Sources & further reading 2
  1. Atzei, Bartoletti & Cimoli — A Survey of Attacks on Ethereum Smart Contracts (2017)
  2. Tversky & Kahneman — Judgment under Uncertainty (1974)

Circulate this file

Annotations are reserved for archive members.

Sign in to annotate