$885 Million in Losses from Outside-Scope DeFi Attacks
A troubling report reveals that audited DeFi protocols lost $885 million to attacks occurring outside the defined audit scopes, revealing critical gaps in security assurance.

Overview of DeFi Audit Losses
In the decentralized finance (DeFi) sector, the term "audited" is often taken as a guarantee of security. However, a recent study reveals that a significant portion of losses in audited protocols stem from attacks occurring outside the defined audit parameters. The research conducted by security firm ack3 and the Czech Technical University analyzed incidents from the first half of 2026, identifying $939.86 million in losses across 135 reported cases.
Within this investigation, researchers classified the audit presence of 68 incidents, ultimately determining that 67.6% of these attacks were outside any identifiable audit scope. Astonishingly, these outside-scope attacks accounted for 94.4% of the total losses. These findings highlight a critical gap in user assurance and the effectiveness of audits in ensuring the security of DeFi systems.
Breakdown of Audit Scope Losses
| Audit Status | Number of Incidents | Total Losses (in millions) |
|---|---|---|
| Outside scope | 46 | $680.97 |
| Inside scope | 20 | $40.27 |
| Unresolved | 2 | $0.22 |
Significant Cases Influencing the Study
The study reveals that two major incidents dominated the overall loss statistics. Excluding the $292 million attributable to Kelp DAO and the $285 million from Drift Protocol left a remaining $103.97 million attributed to outside-scope attacks. This narrowed loss still represented 72.1% of the losses among the audited incidents considered in the study. This indicates a systematic issue where even re-evaluated systems can remain vulnerable if recent changes were not included in the audit assessments.
Responsiveness to Attacks
The pace of responses to detected vulnerabilities also plays a role. The ICON Network experienced a replay exploit where an attacker repeatedly submitted valid withdrawal messages due to a flaw in how withdrawal verification was interpreted. The attack happened between 02:08 UTC and 06:18:54 UTC with a response delay of about 90 minutes from the first automated alert to when full containment measures were enacted. Notably, during this time, users saw significant withdrawals totaling 119.866 million ICX and 531,600 bnUSD.
Audit Gaps in Practice
Case Study: ICON Network
Interestingly, despite an external audit conducted prior to the attack, certain crucial aspects of the contract's implementation fell outside the reviewed boundaries. For instance, the mismatch between the unique message signature and the withdrawal path logic represented a critical audit gap, one that rendered the audit of limited utility. The findings highlight the inadequacy of relying solely on audit badges without deeper examination of specific system pathways.

Case Study: aelf Incident
In contrast, the aelf incident offers a case where the existing audits could not be directly connected to the runtime vulnerabilities exploited. A breach on August 18 led to unauthorized smart contract activity from encoded .NET assemblies, exposing weaknesses in transaction parameter checks and isolation protocols. Although audit records indicated that previous assessments found no issues, they failed to correlate directly with the attack path taken, illustrating that audit findings can become outdated if not continuously aligned with system functionality.
User Assurance and Audit Limitations
As the landscape of DeFi continues to evolve, it is clear that a dated audit alone does not guarantee protection against loss. The study illustrated that assurance needs to be tied closely to a project’s current operational status. Users should be asking specific questions regarding audit efficacy: Which smart contract components were included? Were recommendations acted upon following an audit? How quickly was a response initiated after an issue was detected?
Key Takeaways
- 67.6% of audited incidents were outside the defined audit scope.
- Audit shortcomings led to 94.4% of reported losses.
- Response delays highlighted a significant gap in incident containment, with ICON Network facing 90 minutes of exposure.
- Continuous alignment of audit findings with current system status is crucial for maintaining security.
Future Considerations for DeFi Investors
The findings from this study hold critical implications for DeFi investors. The notion that audits alone can serve as a safety net is misleading, as the audit scope does not encapsulate the complete risk landscape. It encourages a paradigm shift in how investors approach security in DeFi projects. Users are urged to seek detailed reports on audits, the recovery status of compromised assets, and whether necessary fixes have been implemented following vulnerabilities.
More transparency continues to be essential in bridging these gaps, ensuring that even newly added components are evaluated comprehensively before users decide to stake their assets. The overarching message is clear: Past audit findings don’t automatically ensure future security; investors must actively engage with the evolving landscape to secure their interests.
Frequently Asked Questions
