The Audit Gap in Blockchain Security: A Four-Year Empirical Study of Public Audit Findings and Real-World Exploit Incidents
This empirical study of Web3 security from 2022 to 2026 reveals a critical disconnect between stable audit findings and real-world exploit losses, demonstrating that while audits focus on technical vulnerabilities, the majority of financial damages stem from non-technical vectors like social engineering and exhibit extreme concentration in a few massive incidents.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the world of Web3 (blockchain and cryptocurrency) as a massive, bustling city where people build digital banks, bridges, and vaults to hold their money. This paper is like a four-year-long investigation into why, despite hiring the best security guards (auditors) to check the blueprints of these buildings, the city still loses billions of dollars to thieves.
Here is the story of the investigation, broken down into simple parts:
1. The Two Different Worlds
The researchers looked at two very different lists of data:
- The "Blueprint Check" List: This contains 23,818 notes from security firms who reviewed code. They found things like "this door handle is weak" or "this wall is made of flimsy material."
- The "Heist" List: This contains 218 real-world stories of money being stolen, totaling about $7.76 billion.
The big question was: Do the things the security guards warn us about match the things that actually get stolen?
2. The Great Mismatch (The "Audit Gap")
The answer is a loud no. The two lists look completely different, like comparing a list of "things that might break in a car engine" with a list of "reasons people actually get into car accidents."
- What the Auditors Found: The security guards spent most of their time finding tiny, technical glitches in the code itself. They worried about things like "logic errors" (the code doing the wrong math) or "access control" (who has the key). These made up the vast majority of their reports.
- What Actually Happened: The thieves didn't care about the code's math. They mostly stole money by:
- Tricking people: Phishing emails or social engineering (pretending to be someone else).
- Stealing keys: Grabbing the private passwords that control the vaults.
- Hacking the supply chain: Stealing the tools used to build the vault, rather than breaking the vault itself.
The Analogy: Imagine a bank hires a team to check the steel of its vault door. The team spends months finding tiny cracks in the steel (the audit). But the thieves don't break the door; they wait for a guard to walk out, trick him into giving them the key, or steal the blueprints from the architect's desk. The audit was perfect for the door, but it didn't look at the guard or the desk.
3. The "Super-Storm" Effect
The paper also discovered that money losses in this world don't happen evenly. It's not like rain falling gently every day. It's more like a hurricane.
- The 80/20 Rule on Steroids: Just 8 massive heists accounted for more than half of all the money lost in four years.
- The "Average" is a Lie: If you try to guess the risk by looking at the "average" theft, you will be wrong. Most thefts are small, but a few are so huge they wipe out everything else. The paper warns that planning for the "average" is like planning for a sunny day when a tsunami is coming.
4. The "Human" Factor
The most surprising finding is that the biggest losses come from human errors, not computer bugs.
- In the last few years, over half of all money lost was due to people being tricked, keys being stolen, or bad management.
- The security audits mostly checked the code, but they rarely checked the people holding the keys or the computers the people used to sign transactions.
5. The Conclusion: We Need Two Types of Security
The paper concludes that we can't just rely on one type of security guard.
- The Code Auditors are great at finding bugs in the software (the "blueprint").
- The Operational Guards are needed to protect the people, the keys, and the processes (the "security guard's uniform and the guard's mind").
The study says that currently, the industry is very good at checking the blueprints but terrible at protecting the people holding the keys. To stop losing billions, we need to treat these two jobs as partners, not substitutes. We need to check the code and check the human behavior.
In short: The security experts are looking under the streetlamp for lost keys because the light is good there (the code), but the thieves are taking the keys from the dark alley (the people and processes) where no one is looking.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.