Why did audited DeFi protocols lose $885M to out-of-scope attacks in H1 2026?

Audited DeFi protocols lost $885 million in H1 2026 because hackers exploited vulnerabilities that were intentionally excluded from the scope of security audits. This shift highlights a dangerous gap where 72.1% of losses now stem from operational and off-chain weaknesses rather than smart contract code errors.
Why did audited DeFi protocols lose $885M to out-of-scope attacks in H1 2026?

Audited DeFi protocols lost a total of $885 million in the first half of 2026 because attackers bypassed audited smart contract code to exploit vulnerabilities that were marked as "out-of-scope." According to a preprint study from ack3, after excluding two major H1 2026 outliers, a staggering 72.1% of all stolen funds resulted from exploits targeting components that security firms were never hired to review. This data confirms that while smart contract logic is becoming more resilient, the infrastructure surrounding these protocols remains highly vulnerable.

The findings indicate a significant shift in hacker tactics throughout 2026. Instead of hunting for complex bugs in the core code, malicious actors are increasingly targeting operational flaws, such as compromised private keys, front-end website injections, and vulnerabilities in cross-chain bridges that are often excluded from standard audit agreements to reduce costs. Recent security incidents in August 2026 have reinforced this trend, showing that even protocols with multiple "gold-standard" audits are susceptible if their administrative controls or off-chain dependencies are neglected.

For the US market, this report serves as a warning for both retail investors and institutional liquidity providers. The term "audited" is frequently used as a marketing tool to signal safety, yet this data suggests it may provide a false sense of security. As the DeFi sector matures in 2026, the lack of standardized audit scopes is likely to draw increased scrutiny from US regulators, including the SEC and CFTC, who are looking for ways to mandate more comprehensive risk disclosures for decentralized platforms.

Moving forward, investors should watch for a transition toward "full-stack" security reviews that cover the entire lifecycle of a transaction, including the UI/UX and deployment scripts. The industry is reaching a tipping point where a single code audit is no longer sufficient for risk mitigation. Protocols that adopt continuous real-time monitoring and holistic security frameworks will likely be the ones to maintain user trust and total value locked (TVL) as the threat landscape evolves through the remainder of 2026.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.