Audited DeFi protocols lost most of their money to attacks their audits never covered

3 min read
Audited DeFi protocols lost most of their money to attacks their audits never covered
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Topics in article

A new academic study of 2026's first-half DeFi hacks finds that once a protocol had a public pre-incident audit, the attacks that actually hit it overwhelmingly struck code, components, or systems the audit never covered. Two case studies, ICON Network and aelf, show what an audit boundary misses in practice, and how long it can take a team to contain a breach once one appears.

A gap between audit and losses

Researchers affiliated with security company ack3 and the Czech Technical University in Prague examined 135 reported DeFi incidents from the first half of 2026, totaling $939.86 million in attributed losses. They found identifiable public pre-incident audits for 68 of those incidents.

Within that 68-incident subset, the researchers classified 46 attack paths as falling outside every audit scope they could identify, 20 as inside at least one scope, and two as unresolved. The outside-scope group made up 67.6% of the incidents but 94.4% of the reported losses in that subset — $680.97 million of $721.24 million.

Two large cases dominate that figure. After excluding $292 million at Kelp DAO and $285 million at Drift Protocol, the outside-scope share falls to 72.1% of losses in the same subset, or $103.97 million of $144.24 million. The researchers note the study cannot establish that falling outside audit scope caused each loss, only that the two variables often diverge.

ICON's replay exploit slipped through a signature gap

ICON Network's Aug. 27 replay exploit shows how a reviewed system can still fail at the seam between two checks. According to the ICON Foundation's postmortem, a migration contract used the high bits of a withdrawal message's serial number to judge uniqueness, while the cryptographic signature covered only the low 256 bits. An attacker exploited that mismatch to resubmit two signed withdrawal messages 1,492 times over about 20 minutes, with 1,490 calls succeeding.

The replays released 119.866 million ICX and 531,600 bnUSD. ICON put the confirmed net loss at about 150.2 ETH plus 31,204 USDC, and said 531,600 bnUSD and 1.366 million SODA had since been recovered. The migration contract had undergone an external audit with the recommendations implemented, and the relay logic had its own dedicated review — but the specific mismatch between the uniqueness check and the signed value fell outside those findings.

Detection also lagged: ICON's first alert fired at 02:08 UTC, about seven minutes into the exploit; staff opened an investigation around 03:40, paused the affected contract at 03:53, and halted the network at 06:18:54. ICON attributed the delay to alert tuning, since the alert class had produced false positives during unrelated connectivity incidents.

aelf's runtime breach still can't be tied to an audit

aelf's August incident cuts the other way. The company announced a network pause on Aug. 18, and its Aug. 26 update said an unauthorized smart contract had used transaction parameters to push encoded .NET assemblies into the node execution path. aelf identified 155 associated transactions and five unique payload assemblies capable of host command execution and node-key access, though it said this did not prove every assembly ran or that data was exfiltrated.

As of Sept. 11, aelf's public status remained provisional, with no incident-specific update since Aug. 26. Its standing security documentation says the network's contracts underwent multiple audits with no issues found, but the available material does not connect a specific pre-incident report to the runtime path described in August.

Source: CryptoSlate

Trading involves risk.

Most traded markets

BTC / USD
+0.18% 77,290.0
EUR / USD
+0.01% 1.15975
ETH / USD
-0.49% 2,507.66
USD / JPY
-0.05% 153.427
BNB / USD
-0.64% 722.07
GBP / USD
+0.03% 1.35279
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Crypto News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.