WikiBit 2026-07-20 20:07Institutional investors are shifting focus beyond smart contract audits after traditional trust signals failed to predict crypto exploits, according to Hacken‘s Q2 2026 report. Only 9% of 1,427 tracked projects had third-party monitoring, and compromised keys, signers, and infrastructure accounted for 88.3% of roughly $764 million stolen. Projects lacking ongoing operational security evidence face higher risk perception and reduced investment. Abraxas Capital noted that inadequate security relative to capital at risk often leads to rejection, while Moody’s Ratings cited operational resilience as the practical evaluation lens. Due diligence now includes signer-set changes, timelocks, and incident-response readiness. Fourteen exploited projects had prior audits, but most losses stemmed from areas beyond conventional smart contract reviews.
Institutional investors are looking beyond smart contract audits after traditional trust signals such as prior audits and operating history failed to predict which crypto projects would be exploited, according to Hacken.
In its Q2 2026 Security & Compliance Report, Hacken said that only 9% of 1,427 tracked projects had third-party monitoring, while 4% combined monitoring with an active bug bounty and a security audit. The report highlighted that compromised keys, signers and infrastructure accounted for 88.3% of the roughly $764 million stolen during the quarter.
Hacken said projects unable to provide ongoing evidence of operational security may face higher perceived risk, reduced investment and more difficult access to insurance or counterparties.
Contributors to the report included Federico Bagiotti, group head of risk management at Abraxas Capital, who said “inadequate security relative to the capital at risk” was the signal that most often led the firm to reject an otherwise attractive position. Rajeev Bamra, Moody‘s Ratings’ head of digital economy strategy, said that operational resilience had become “the practical lens” through which institutions evaluated security, compliance and governance.
Operational security becomes an allocation test
The report said institutional due diligence is beginning to include signer-set changes, collateral backing, third-party dependencies, incident-response readiness and the scope and recency of audits. Abraxas said it now explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls and single-key or single-verifier dependencies.
The shift has also appeared in regulatory and industry scrutiny. In a July 10 Cointelegraph report, BitGo Chief Operating Officer Jody Mettler said institutional clients had begun asking more detailed questions about custody providers access controls, incident response and business continuity as European regulators examined operational resilience under the Digital Operational Resilience Act (DORA).
Related: Crypto hacks fell 47% in H1 but ecosystem is no safer: CertiK
Hacken said 14 projects exploited in the second quarter had previously been audited. However, most losses stemmed from areas outside the scope of conventional smart contract reviews. The affected surfaces included signer devices, bridge validators, backend infrastructure, admin keys and older contracts that remained live despite being deprecated.
The dataset covered 1,427 projects with market caps above $1 million, drawn from assets listed across the top 50 centralized exchanges by CoinGecko Trust Score. Hacken excluded wrapped assets, stablecoins and tokenized real-world assets. Its data relied on publicly observable and disclosed controls, which means that private arrangements may not be captured.
Disclaimer:
The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.
Over 95% of Coinbases code is now written with help of AI
WikiBit 2026-07-15 09:34Bitcoin Clings Between $63.8K to $64K as Charts Flash High-Stakes Bull-Bear Showdown
WikiBit 2026-07-16 21:15Visa says stablecoins will power micro-commerce in AI agentic economy
WikiBit 2026-07-16 16:29Silver tumbles as energy-driven inflation fears hit sentiment
WikiBit 2026-07-16 20:45Bitcoin rally has “borrowed strength” without spot demand, Bitfinex says
WikiBit 2026-07-16 15:31Stanford study says 5-minute Bitcoin prediction markets enable settlement manipulation
WikiBit 2026-07-16 21:17Bitcoin whale moves $383 million in BTC after 8 years of dormancy: onchain data
WikiBit 2026-07-16 14:54California duo accused of laundering crypto from fentanyl and meth sales
WikiBit 2026-07-16 14:33Czech Republic tells ISPs to block Polymarket after gambling blacklisting
WikiBit 2026-07-16 16:43Keyrock closes deal for BlockFills institutional trading and brokerage assets
WikiBit 2026-07-16 22:420.00