AI · CryptoSlate
Audited DeFi protocols shed $885 million to attacks that occurred completely outside their audit scopes
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
In decentralized finance, “audited” is often presented as a verdict on an entire project.
Key facts
- Removing Kelp DAO and Drift Protocol left $103.97 million of $144.24 million outside scope, or 72.1%
- Two large cases also dominate it: after excluding $292 million at Kelp DAO and $285 million at Drift Protocol, the outside-scope share falls to 72.1% of losses in the same audited-incident subset
- For that 68-incident group, outside-scope incidents accounted for $680.97 million of $721.24 million in reported losses, producing the 94.4% figure
- Researchers affiliated with security company ack3 and the Czech Technical University in Prague examined 135 reported incidents from the first half of 2026, with $939.86 million in attributed losses
Summary
01 Removing Kelp DAO and Drift still leaves 72.1% of audited-subset losses outside identified scope. 02 ICON’s replay exploit exposed both a code-review gap and a delay between detection and containment. 03 aelf’s runtime compromise cannot yet be mapped to a specific pre-incident audit scope. A new preprint puts a number on that gap.