
⏱ 2 min read
New research quantifies the disconnect between DeFi audit claims and realized security, finding most losses this year came via paths never reviewed.
A newly published analysis of 2026 DeFi incidents exposes a structural gap between ‘audited’ claims and actual project security, with over $900 million in losses arising from attack paths outside reviewed code.
What the Latest DeFi Dataset Really Shows
Security researchers from ack3 and the Czech Technical University in Prague analyzed 135 reported incidents from Jan. 1 to June 29, 2026, attributing $939.86 million in losses. They focused on projects with publicly documented audits. Within a 68-incident subset where the audit record was traceable, the findings were stark: 46 incidents occurred via paths outside every audit scope the team could identify, compared to just 20 where the exploited component was inside scope.
The weight of losses was similarly lopsided: those outside-scope incidents represented 67.6% of the sampled attacks but accounted for 94.4%—over $680 million—of their reported financial impact. While two major exploits (Kelp DAO and Drift Protocol) dominated totals, even when excluded, ‘outside scope’ events still explained most of the remaining losses. Researchers emphasized the analysis is not an audit effectiveness score, but a mapping of where audit lines matched to real-world failures.
The Limits of ‘Audited’ as Risk Assurance
For users and investors, these outcomes challenge how much weight to place on the presence of an audit badge. Audits typically review specified code, versions, and components at a given time—a snapshot, not a living guarantee. Any functionality, upgrade, integration, or operational process outside that perimeter may carry very different risk characteristics.
Contextually, as DeFi ecosystems become more composable and active, the generation and evolution of new contracts or cross-protocol integrations heightens the possibility of blind spots. The dataset reveals that substantial value loss can occur even in purportedly ‘audited’ environments, simply because critical attack paths were never part of the original review. This dynamic is especially pronounced where the complexity of a system or speed of iteration outpaces audit processes.
Signals Worth Tracking From This Study
- Operational risk is tightly linked to audit scope specificity, not audit existence alone.
- Vigilance should extend to tracking code changes, upgradability, or newly added modules post-audit.
- Absence of public documentation on what was excluded from an audit should raise user caution.
- Watch for new frameworks or disclosures that standardize audit coverage transparency in DeFi.
Open Questions: How Will DeFi Accountability Evolve?
Analysts and developers will increasingly focus on both the explicit boundaries and the timeliness of audits. With loss concentration skewed to out-of-scope issues, the pressure will mount for continuous assurance models and for revealing what an audit did not cover. Greater granularity in publicly available audit disclosures could become a new trust marker. For now, users and investors are left to parse the assurance signal amid a landscape of blind spots and evolving risk.
This content is for informational purposes only and does not constitute financial advice.
🧠 HafidWatch Take
If future incident forensics revealed that the majority of losses stemmed from vulnerabilities within the explicitly audited code—rather than outside it—this interpretation would be fundamentally flawed. It would demonstrate that the audit process itself fails to provide reliable security guarantees, invalidating the core assertion that audit boundaries primarily dictate exposure. Such evidence would force a reassessment of the audit’s validity, shifting the focus from incomplete coverage toward intrinsic deficiencies in audit quality and thoroughness.
A close historical example is the 2021 Compound Finance incident, where initial confidence in audits was undermined when an exploit leveraged a subtle bug in audited contracts not detected by multiple reviews. This case highlights how early market optimism about audit sufficiency underestimated complex system risks and contributed to misplaced trust. It underscores the persistent challenge of audit limitations and the evolving necessity for broader, more dynamic verification methods beyond static code reviews.
Daily crypto intelligence. Before the market opens.
Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.
✓ Free forever · ✓ No spam · ✓ 50+ sources monitored


