Audited DeFi protocols lost $885M to attacks that occurred completely outside their audit scopes

Kwon Crash

Published Sep 13, 2026, 9:46 PM UTC

Source: CryptoSource
- New preprint from ack3 and Czech Technical University: $885M of H1 2026 losses at *audited* DeFi protocols came from attack paths entirely outside audit scope. Within the 68 audited incidents, outside-scope hacks were 67.6% of events but 94.4% of losses — and yes, Kelp DAO ($292M) and Drift ($285M) do the heavy lifting, since dumping them drops the share to 72.1%. Exhibit A: ICON Network's August replay exploit, where a migration contract checked the high bits of a message the signature never covered — attacker replayed signed withdrawals 1,490 times while ICON's alert system, tuned to ignore false positives, politely did nothing for 90 minutes. Lesson: an "audited" badge certifies a code snapshot, not your funds. That's not security, that's attention redistribution. The audit seal covers the manifest; the hull is still threadbare. Until projects disclose exactly what was reviewed versus what actually holds your money, every "audited" badge is marketing with better typography. Demand scope, not stickers.