The $885M Blind Spot in DeFi's Audit Obsession
A new preprint from ack3-affiliated researchers and Czech Technical University in Prague found that audited DeFi protocols lost $885 million to attacks that fell completely outside their audit scopes. After excluding two H1 2026 outliers, the outside-scope share sits at 72.1%, and August incidents reinforced the pattern.
Audited DeFi protocols lost $885 million to attacks that happened entirely outside their audit scopes. That's the headline from a new preprint by researchers affiliated with security firm ack3 and the Czech Technical University in Prague, covering 135 reported incidents. Exclude two outliers from the first half of 2026 and the outside-scope share lands at 72.1%. The numbers tell the story.
Here's what matters: an audit isn't a verdict on a protocol. It's an opinion on named code, specific components, specific versions, at one point in time. Everything added afterward sits outside that boundary. Key management, upgrade paths, oracle configuration, front-end hosting, governance execution, the ops runbook nobody opens until something breaks. Frankly, most of that $885 million didn't come from a clever reentrancy bug inside audited contracts. It came from the parts everyone assumed somebody else was watching.
The two H1 2026 outliers were large enough to distort the aggregate, which is exactly why the 72.1% figure after their removal carries more weight than the raw total. August added further operational context, and the pattern didn't budge.
So why does the market still treat a clean audit report like a blanket guarantee? Because it's cheap shorthand. Venture partners want a checkbox. Allocators want a line item in a memo. Nobody gets paid to write "audited, but the multisig keys are held by three people in the same Telegram group." That's my strong opinion, and the data backs it: the gap between what's reviewed and what's live is where the losses live.
From a risk perspective, your exposure isn't the code you reviewed. It's the code, keys, and infrastructure you didn't. Scope documents are the real due diligence artifact here, not the certificate at the end of the PDF. Read the scope first. Then ask what changed since the signature date, and who signed off on it.
Watch the next wave of post-incident disclosures. If teams start publishing scope deltas next to audit reports, this research landed. If they keep shipping certificates and calling it safety, the $885 million is just the opening number.