arXiv · 2608.13792
The ack3 H1 2026 DeFi Incident Dataset: Audit Scope Across 135 Security Incidents
Abstract
Smart-contract audits cover defined artifacts at a specific time, but the label audited is often treated as project-wide assurance. We analyze audit history and incident-path scope across 135 DeFi security incidents using the H1 2026 DeFi Incident Dataset published by cybersecurity company ack3 (https://ack3.ai), covering 1 January to 29 June 2026. The corpus reports USD 939.86 million in attributed loss. Audit history was identified for 68 incidents. Of these, 46 attack paths were outside all identified public pre-incident audit scopes, 20 were inside at least one scope, and 2 were unresolved. Within this 68-incident subset, outside-scope paths represented 67.6% by count and 94.4% of reported loss. The loss-weighted result was concentrated in two large incidents; excluding both reduced the share to 72.1%, while preserving the direction of the result. We also describe audit age, temporal loss distribution, and affected project types. The results show that project-level audit history and incident-path scope are distinct variables.
Explore related subjects
Keep this discovery
Josef Gattermayer, Jan Kalivoda, Arman Bašović. 2026-08-13. The ack3 H1 2026 DeFi Incident Dataset: Audit Scope Across 135 Security Incidents. https://arxiv.org/abs/2608.13792
Cite the original work for its findings. Save a collection to share your selection of sources.