Audits Provide False Sense of Security in DeFi
Audits in decentralized finance (DeFi) often give users a sense of security, but a new study shows that this may not always be the case. Researchers affiliated with ack3 and the Czech Technical University in Prague examined 135 reported incidents from the first half of 2026, with $939.86 million in attributed losses.
They found identifiable public pre-incident audits for 68 incidents, but classified 46 attack paths as outside every audit scope they could identify. This group represented 67.6% of the incidents but 94.4% of their reported losses.
The study highlights a basic assurance problem in DeFi: even if a project claims to have been audited, users may still be unsure whether the live system, the path holding their funds, and the controls around it were reviewed.