Key Takeaways
A preprint reveals that audited decentralized finance protocols suffered 72.1% of losses outside identified audit scopes, highlighting assurance gaps.

According to CryptoSlate, researchers affiliated with security company ack3 and the Czech Technical University in Prague examined 135 reported incidents from the first half of 2026, totaling $939.86 million in losses. For 68 incidents with identifiable public pre-incident audits, 46 attack paths fell outside every identified audit scope, representing 94.4% of losses in that subset. Excluding Kelp DAO and Drift Protocol, the outside-scope share remains 72.1%.
CryptoSlate reported that August incidents further illustrate these boundaries. ICON Network suffered a replay exploit due to a migration contract message uniqueness check mismatch, releasing millions of tokens. Separately, aelf experienced a runtime compromise involving dynamic loading and node execution paths, though available evidence cannot tie it to a specific pre-incident audit scope.
CryptoSlate noted that the study concludes audit history and audit scope are separate variables. A reviewed smart contract does not automatically confer assurance on upgrades, keys, front ends, relays, or oracles. Users need specific, versioned assurance records detailing reviewed components, dependencies, runtime isolation, and incident response measures.
Source & Fact-Check Note
This report is synthesized from coverage by CryptoSlate. Information has been fact-checked and structured for market clarity by CoinQuickly’s research desk.
Read original article at CryptoSlate ↗

