< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

DeFi security research reveals 94% of audited protocol losses occurred outside audit scopes

A new research preprint from security company ack3 and the Czech Technical University in Prague highlights a significant assurance gap in decentralized finance (DeFi) security. By examining 135 reported incidents from the first half of 2026, which resulted in $939.86 million in attributed losses, researchers identified a pattern where attacks frequently occur outside the boundaries of existing audits.

In a subset of 68 incidents that had identifiable public pre-incident audits, 46 attack paths were classified as being outside every identified audit scope. While these outside-scope incidents accounted for 67.6% of the cases in that subset, they represented 94.4% of the reported losses. The study notes that two major incidents—$292 million at Kelp DAO and $285 million at Drift Protocol—heavily influenced these figures; even after excluding them, the outside-scope share remained at 72.1%.

The findings suggest that while a project may truthfully claim to be audited, users often lack clarity regarding whether the live system, fund pathways, and surrounding controls were actually reviewed.

Entities

Czech Technical University in Prague · Drift Protocol · Kelp DAO · ack3