A team we onboarded to Glider Monitor runs 85 contracts across six chains — Ethereum, Arbitrum, Base and three more.
Their dependency graph came back with 2,895 addresses.
That is 34 inherited contracts for every one they deployed. Oracles, routers, proxies, token implementations, and whatever those call in turn. None of it was in anyone's audit scope. None of it sits in their repo. All of it can change without a single person on their team being told.
Worth noting where those 2,895 concentrate: across six deployment chains, the dependency graph clusters onto two. Most teams assume their inherited risk spreads the way their contracts do. It rarely does.
An audit tells you your code was correct on the day someone read it. It says nothing about the 2,895 addresses underneath, and nothing about tomorrow.
Map what you depend on. Then watch it.