Study Says Most Losses in Audited DeFi Incidents Came From Attack Paths Outside Audit Scope
A new preprint paper by researchers affiliated with security firm ack3 and the Czech Technical University in Prague argues that the “audited” label in decentralized finance often says far less than users assume. The study reviewed 135 security incidents reported in the first half of 2026, representing $939.86 million in losses, and identified 68 cases with publicly traceable pre-incident audit records. Within that audited subset, 46 attack paths were classified as falling completely outside any verifiable audit scope, 20 were covered by at least one audit, and two could not be determined. Those out-of-scope incidents accounted for 67.6% of the 68 audited cases by count, but $680.97 million out of $721.24 million by losses, or 94.4%. The paper stresses that this does not measure whether audits are effective, nor does it prove that scope limitations directly caused the losses. The distribution is heavily influenced by two large incidents, Kelp DAO and Drift Protocol. Removing those two brings the out-of-scope loss share down to 72.1%. The paper also uses the August incidents involving ICON Network and aelf to show why a project being audited does not mean its deployed system, operational controls, upgrade paths, runtime environment, or emergency response procedures have all been reviewed. Its broader point is narrow but important: an audit record and actual audit coverage are different things, and users need versioned, time-stamped security records rather than a generic audit badge.








