Skip to content
DeFiNeutral

Audited DeFi protocols face $885M in losses from outside-scope attacks

Source: CryptoSlate
Audited DeFi protocols face $885M in losses from outside-scope attacks

A recent audit from an ack3-affiliated preprint has revealed that audited decentralized finance (DeFi) protocols have suffered a staggering $885 million in losses due to attacks that occurred entirely outside the scopes of their audits. The study highlighted that when excluding two outlier incidents from the first half of 2026, the share of losses attributed to outside-scope events stands at an alarming 72.1%. This insight sheds light on the vulnerabilities that persist in the DeFi space, despite the presence of audits intended to bolster security and confidence among users.

The context for this revelation is crucial, as the DeFi sector has been rapidly growing and evolving, attracting investments and users alike. However, with this growth comes an increase in risks, particularly from malicious actors who exploit gaps in security measures. Audits are designed to assess and mitigate risks within the defined scope of a protocol, but this new data indicates that many attacks are occurring in areas that may not have been thoroughly examined. This calls into question the effectiveness of audits as a standalone security measure in an increasingly complex landscape.

The implications of this finding are significant for the broader market. As the DeFi ecosystem continues to mature, investors and users may begin to reassess their trust in audited protocols, especially if they perceive a disconnect between audit assurances and real-world vulnerabilities. The $885 million in losses could lead to increased scrutiny from regulators and investors alike, potentially influencing the trajectory of DeFi investments and innovations. This situation raises concerns about the sustainability of current practices in the industry and the need for enhanced security measures.

Industry reactions to this report have been mixed, with some experts acknowledging the necessity of audits while emphasizing the importance of a more holistic approach to security that includes continuous monitoring and adaptation to emerging threats. Others argue that the findings highlight a critical gap in current auditing practices and that protocols must go beyond traditional audits to protect against an evolving threat landscape. Trust in DeFi may hinge on how quickly the industry can address these vulnerabilities and reinforce security measures.

Looking ahead, it will be essential for DeFi protocols to reassess their security strategies in light of these findings. This may involve implementing more rigorous testing procedures, adopting real-time monitoring solutions, and fostering collaboration within the industry to share threat intelligence. As the landscape of cyber threats continues to evolve, the DeFi sector must adapt to ensure the safety of user funds and maintain the integrity of its protocols.

CoinMagnetic

CoinMagnetic Team

Crypto investors since 2017. We trade with our own money and test every exchange ourselves.

Updated: September 2026

Get news first?

Follow our Telegram channel – we post the top news and analysis.

Follow the channel

Related news