Skip to main content
Back to news
SafetyMajor story — Significance is rated automatically and is not a price signal.

Audited DeFi Protocols Lost $885 Million to Attacks Outside Audit Scopes

(18 days ago) · 1 source · Summarized by CryptoBipto — how we make this

A report found that DeFi protocols that had undergone security audits still lost a combined $885 million to exploits that fell entirely outside the scope of those audits. The attacks targeted areas such as infrastructure, governance, and off-chain components rather than the smart contract code that audits typically review.

WHY IT MATTERS

When a DeFi project says it has been "audited," many newcomers assume that means the entire system has been checked for safety, similar to how a building inspection might cover the whole structure. In reality, a DeFi audit is more like hiring someone to check only the electrical wiring in one room. The plumbing, the foundation, and the locks on the doors might never be examined. This report shows that attackers have exploited exactly those unchecked areas, costing users hundreds of millions of dollars. For anyone using DeFi, it is important to understand that an audit covers only a limited part of a protocol's security and is not a guarantee against all types of attacks.

Security audits in decentralized finance generally focus on reviewing smart contract code for vulnerabilities before a protocol launches or upgrades.

Read the full analysis with a CryptoBipto membership

Members can read the full analysis of every story, not just the headline.

Get started

RELATED

DeFi SecuritySmart Contract AuditsProtocol ExploitsRisk Management