DeFi Audits Provide False Sense of Security
A new study on decentralized finance (DeFi) audit scopes reveals that even when projects claim to be audited, they may not provide adequate assurance for users. Researchers affiliated with ack3 and the Czech Technical University in Prague examined 135 reported incidents from the first half of 2022, with $939.86 million in attributed losses.
They found identifiable public pre-incident audits for 68 incidents. Within that subset, the authors classified 46 attack paths as outside every audit scope they could identify, 20 as inside at least one scope and two as unresolved. The outside-scope group represented 67.6% of the incidents but 94.4% of their reported losses.
The study's findings highlight a basic assurance problem in DeFi. A project may truthfully say it was audited while leaving users unable to tell whether the live system, the path holding their funds and the controls around it were reviewed.