started · updated
DeFi security research reveals 94% of audited protocol losses occurred outside audit scopes
A new research preprint from security company ack3 and the Czech Technical University in Prague highlights a significant assurance gap in decentralized finance (DeFi) security. By examining 135 reported incidents from the first half of 2026, which resulted in $939.86 million in attributed losses, researchers identified a pattern where attacks frequently occur outside the boundaries of existing audits.
In a subset of 68 incidents that had identifiable public pre-incident audits, 46 attack paths were classified as being outside every identified audit scope. While these outside-scope incidents accounted for 67.6% of the cases in that subset, they represented 94.4% of the reported losses. The study notes that two major incidents—$292 million at Kelp DAO and $285 million at Drift Protocol—heavily influenced these figures; even after excluding them, the outside-scope share remained at 72.1%.
The findings suggest that while a project may truthfully claim to be audited, users often lack clarity regarding whether the live system, fund pathways, and surrounding controls were actually reviewed.
Entities
Czech Technical University in Prague · Drift Protocol · Kelp DAO · ack3