
Photo: Illustrative
Crypto Institutions Move Beyond Audits As Old Trust Signals Fail To Predict Hacks
Institutional investors are shifting their due diligence approach after finding that traditional trust markers, like prior smart contract audits and a project's operating history, failed to predict which crypto platforms would actually get exploited, according to a new Q2 2026 security report from Hacken.

Institutional investors are shifting their due diligence approach after finding that traditional trust markers, like prior smart contract audits and a project’s operating history, failed to predict which crypto platforms would actually get exploited, according to a new Q2 2026 security report from Hacken.

The report tracked 1,427 crypto projects and found that only 9% had third-party monitoring in place, while just 4% combined monitoring with both an active bug bounty and a security audit. Compromised keys, signers, and infrastructure accounted for 88.3% of the roughly $764 million stolen during the quarter, pointing to weaknesses that conventional audits typically don’t catch. Hacken noted that projects unable to show ongoing proof of operational security may face higher perceived risk, less investment, and greater difficulty securing insurance or counterparties.
Operational Security Becomes A Core Screening Factor
According to contributors cited in the report, institutional due diligence is expanding to cover signer set changes, collateral backing, third-party dependencies, incident-response readiness, and how recent and thorough past audits actually were. Abraxas Capital said it now specifically checks for timelocks, withdrawal-address whitelisting, multiparty controls, and any reliance on a single key or verifier. Moody’s Ratings described operational resilience as the practical framework institutions now use to judge security, compliance, and governance together.
Regulatory Pressure Adds To The Shift
The trend has coincided with growing regulatory scrutiny, as European rules under the Digital Operational Resilience Act push custody providers to answer more detailed questions from institutional clients about access controls and business continuity. Hacken found that 14 projects exploited during the quarter had previously passed audits, but most of the resulting losses came from areas like signer devices, bridge validators, backend systems, admin keys, and outdated contracts still left active. The dataset covered projects with market caps above $1 million listed on top exchanges, excluding wrapped assets, stablecoins, and tokenized real-world assets.
Live market reaction
Disclaimer
This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.
Start trading
with BloFin today
Up to $500 sign-up bonus and zero-fee trading on your first 30 days.
Buy crypto nowⓘ You will be redirected to BloFin
About the author

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.


