An audit examines a specific version of specific contracts for a limited time. The report lists findings by severity and states what was excluded, which is often the most informative part: off-chain components, economic design, oracle assumptions and governance are frequently out of scope.
Audited protocols are exploited regularly. Causes include code changed after the review, findings acknowledged but not fixed, economic attacks that were never in scope, and compromised keys that no code review could prevent. "Audited" on a landing page means almost nothing on its own.
Read the report itself: which firm, which commit hash, how many critical findings and whether they were resolved, and whether the deployed address matches what was reviewed. Multiple audits plus a live bug-bounty and years of uneventful operation are better evidence than any single badge.
Related: bug-bounty, admin-key-risk, flash-loan-attack, honeypot-token