Audits Fall Short: DeFi Incidents Exceed Audit Scope
A new study published in a preprint has shed light on the limitations of audits in decentralized finance (DeFi). Researchers affiliated with ack3 and the Czech Technical University in Prague examined 135 reported incidents from the first half of 2026, with $939.86 million in attributed losses.
The study found that out of 68 identifiable public pre-incident audits, 46 attack paths were outside every audit scope they could identify, while 20 were inside at least one scope and two were unresolved.
The researchers noted that the majority of reported losses ($680.97 million) occurred in incidents where the audit path was outside the reviewed code or components. This raises concerns about the effectiveness of audits in providing assurance to users.
The study highlights the importance of understanding what is covered by an audit and what may be left out, particularly in DeFi protocols that are constantly evolving.