DeFi Audits Miss 72% of Attack Vectors, $885M Study Reveals
In brief
- 135 DeFi incidents in H1 2026 totaled $939.86 million in losses across audited and unaudited protocols
- 46 of 68 audited protocols suffered attacks via vectors completely outside their audit scope
- Excluding outliers, outside-scope incidents represented 72.1% of total audited-subset losses
- Audits typically exclude upgrades, keys, front ends, oracles, and incident response mechanisms
- Study exposes critical gap between audit coverage and actual system security exposure
The audit scope problem
Of 68 incidents with identifiable public pre-incident audits, 46 attack paths were classified as outside every audit scope they could identify, representing 94.4% of reported losses in that subset. For that group, outside-scope incidents accounted for $680.97 million of $721.24 million in reported losses.
After excluding $292 million at Kelp DAO and $285 million at Drift Protocol, the outside-scope share fell to 72.1% of losses in the audited-incident subset. Even after removing the two largest outliers, nearly three-quarters of losses still traced to attack vectors audits didn't examine.
The core issue: audit history and audit scope are different variables. A reviewed smart contract doesn't automatically confer protection on upgrades, privileged keys, front ends, relayers, oracles, cloud services or incident-response processes. A protocol can truthfully say it was audited while its live system, the path holding user funds, and the controls around those funds remain unreviewed.
"A reviewed smart contract does not automatically confer the same assurance on an upgrade, privileged key, front end, relayer, oracle, cloud service or incident-response process." — ack3-affiliated researchers
Real-world example: ICON Network
The ack3 dataset covered incidents from January 1 through June 29, 2026, with 122 graded as confirmed and 13 as likely. One August incident adds operational context: ICON Network's migration contract used the high bits of a withdrawal message's serial number to decide uniqueness, while the cryptographic signature covered only the low 256 bits. By changing the unsigned high bits, an attacker resubmitted two legitimately signed withdrawal messages 1,492 times over about 20 minutes, with 1,490 calls succeeding.
Study limitations
The research carries important caveats. The study lacks an unexploited comparison group and a measure of how long each system was exposed, and cannot establish whether audited protocols are safer overall or estimate incident probability. The preprint was produced with the dataset publisher, and two authors are affiliated with ack3, which sells security reviews.
Still, the finding holds weight. It doesn't claim audits are useless. It shows that users can't assume an audit label means their funds are protected across the entire system they're interacting with. The gap between what gets audited and what gets exploited remains wide.


