← Latest papers
💻 computer science

The ack3 H1 2026 DeFi Incident Dataset: Audit Scope Across 135 Security Incidents

This paper analyzes the H1 2026 DeFi Incident Dataset to reveal that 67.6% of security incidents and 94.4% of attributed losses occurred via attack paths outside the scope of identified pre-incident smart contract audits, demonstrating a critical distinction between project-level audit history and specific incident-path coverage.

Original authors: Josef Gattermayer (ack3, Czech Technical University in Prague), Jan Kalivoda (ack3), Arman Bašović (Czech Technical University in Prague)

Published 2026-08-17
📖 5 min read🧠 Deep dive

Original authors: Josef Gattermayer (ack3, Czech Technical University in Prague), Jan Kalivoda (ack3), Arman Bašović (Czech Technical University in Prague)

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the digital world of money, known as Decentralized Finance or DeFi, as a massive, bustling city built entirely out of invisible, self-running machines. In this city, there are no banks with managers; instead, there are "smart contracts"—complex computer programs that automatically move money around based on strict rules. Because these machines hold billions of dollars, people hire "auditors," who are like high-tech building inspectors, to check the blueprints before the machines are turned on. The big question everyone asks is: "If a building has an inspector's stamp of approval, is it safe?" This paper dives into that exact question, but with a twist. It suggests that having a stamp doesn't mean the whole building is safe; it might just mean the inspector looked at the front door while the thief was sneaking in through the back window. The authors are trying to figure out how often these "stamps" actually cover the specific path a hacker takes to steal the money.


The Great "Audit" Mismatch: When Inspectors Miss the Real Danger

In the first half of 2026, a cybersecurity team called ack3 decided to play detective. They gathered a massive list of 135 security disasters in the DeFi city, where hackers managed to steal a staggering $939.86 million. That's nearly a billion dollars vanished into the digital ether! The team wanted to solve a mystery: When these disasters happened, had the projects been "audited" (inspected) beforehand? And if they had, did the auditors actually look at the specific part of the system the hacker broke?

The answer they found is a bit like checking a car for safety. Imagine you hire a mechanic to inspect a car. He checks the engine, the brakes, and the tires, and gives it a "Safe to Drive" sticker. But then, the car gets stolen because the thief picked the lock on the glove box—a part the mechanic never looked at. The car was "inspected," but the specific part that failed was outside the inspection scope.

The researchers looked at 68 of these 135 disasters where they could find the original inspection reports. Here is the shocking part: In 46 of those cases (that's 67.6% of the inspected projects), the hacker didn't break the part the auditors checked. They broke something else entirely! Maybe they hacked the server that runs the website, stole a password from a cloud computer, or tricked a bridge that connects two different digital worlds. These are all things that were outside the scope of the audit.

When you look at the money lost, the picture gets even more dramatic. The "outside-scope" disasters accounted for 94.4% of the total money lost in this group. That means almost all the stolen cash came from projects where the auditors had looked at the wrong part of the machine.

To make sure this wasn't just a fluke caused by two massive heists, the researchers did a little math trick. They took out the two biggest thefts (one was $292 million and the other $285 million) and looked at the rest. Even without those giants, the "outside-scope" disasters still made up 72.1% of the remaining losses. The pattern held strong: the auditors were often looking at the wrong thing.

But what about the 20 incidents where the hacker did break the part the auditors checked? The researchers found that for these, the "inspection" was often quite old. The average time between the audit and the hack was 18 months. In the tech world, that's like an architect checking a blueprint in 2024, but the building isn't finished until 2026, and in the meantime, the builders changed the wiring, added new rooms, and swapped the doors. The "sticker" was still there, but the building had changed.

The paper also looked at what got hacked. The biggest category was "other protocols," which is a catch-all for weird, complex systems that don't fit into simple boxes like "lending" or "exchanges." These complex systems lost the most money, totaling $392.86 million. Bridges (which move money between different digital networks) and perpetual futures exchanges were also major targets.

So, what's the big takeaway? The authors aren't saying audits are useless. They are saying that the label "Audited" is often treated like a magic shield that covers the whole project, when in reality, it's more like a specific receipt for a specific job done at a specific time. If a project says, "We were audited," it doesn't mean the whole system is safe; it just means some part of it was checked at some point.

The researchers suggest that we need to stop looking at the "Audited" label as a guarantee. Instead, we need to ask: "Did they check the exact code that got hacked?" and "How long ago was that check?" Because in the fast-moving city of DeFi, a safety check from a year ago might not protect you from a new kind of thief today. The lesson is clear: Just because the inspector signed the paper doesn't mean the whole house is safe from burglars.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →