arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ack3 H1 2026 DeFi 事件数据集:135 起安全事件的审计范围

The ack3 H1 2026 DeFi Incident Dataset: Audit Scope Across 135 Security Incidents

Josef Gattermayer, Jan Kalivoda, Arman Bašović

arXiv 2608.13792首次发表:更新:

AI 中文总结

该研究基于 ack3 发布的 H1 2026 DeFi 事件数据集,分析 135 起 DeFi 安全事件的审计历史与路径范围,发现项目级审计历史和事件路径范围是不同变量,超范围路径占比高且损失占比大。

AI 中文摘要

智能合约审计会覆盖特定时间的已定义制品,但“已审计”标签常被视为项目级别的保证。我们使用网络安全公司 ack3 发布的 H1 2026 DeFi 事件数据集(覆盖 2026 年 1 月 1 日至 6 月 29 日),分析了 135 起 DeFi 安全事件的审计历史和事件路径范围。该语料库报告的归因损失达 9.3986 亿美元。其中 68 起事件可识别审计历史:46 条攻击路径在所有已识别的公开事件前审计范围之外,20 条在至少一个审计范围内,2 条未解决。在这 68 起事件子集中,超范围路径按数量占比 67.6%,按报告损失占比 94.4%。损失加权结果集中在两起大型事件中;排除这两起后,该占比降至 72.1%,但结果方向保持不变。我们还描述了审计时长、时间损失分布和受影响项目类型。结果表明,项目级审计历史与事件路径范围是不同的变量。

英文摘要

Smart-contract audits cover defined artifacts at a specific time, but the label audited is often treated as project-wide assurance. We analyze audit history and incident-path scope across 135 DeFi security incidents using the H1 2026 DeFi Incident Dataset published by cybersecurity company ack3 (https://ack3.ai), covering 1 January to 29 June 2026. The corpus reports USD 939.86 million in attributed loss. Audit history was identified for 68 incidents. Of these, 46 attack paths were outside all identified public pre-incident audit scopes, 20 were inside at least one scope, and 2 were unresolved. Within this 68-incident subset, outside-scope paths represented 67.6% by count and 94.4% of reported loss. The loss-weighted result was concentrated in two large incidents; excluding both reduced the share to 72.1%, while preserving the direction of the result. We also describe audit age, temporal loss distribution, and affected project types. The results show that project-level audit history and incident-path scope are distinct variables.

Comments6 pages, 6 figures. Dataset: https://doi.org/10.5281/zenodo.21906487

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑