Institutional investors are looking beyond smart contract audits after traditional trust signals such as prior audits and operating history failed to predict which crypto projects would be exploited in Q2 2026, according to Hacken. The shift follows a quarter in which compromised keys, signers, and infrastructure accounted for 88.3% of roughly $764 million stolen, as detailed in Hacken's Q2 2026 Security & Compliance Report. Federico Bagiotti, group head of risk management at Abraxas Capital, said "inadequate security relative to the capital at risk" was the signal that most often led the firm to reject an otherwise attractive position, while Rajeev Bamra, Moody's Ratings' head of digital economy strategy, noted that operational resilience had become "the practical lens" through which institutions evaluated security, compliance, and governance.
Hacken's Q2 2026 Security & Compliance Report tracked 1,427 crypto projects with market caps above $1 million. The report found that only 9% of these projects had third-party monitoring, while 4% combined monitoring with an active bug bounty and a security audit. The dataset covered assets listed across the top 50 centralized exchanges by CoinGecko Trust Score, excluding wrapped assets, stablecoins, and tokenized real-world assets. Hacken noted that its data relied on publicly observable and disclosed controls, meaning private arrangements may not be captured.
The report stated that projects unable to provide ongoing evidence of operational security may face higher perceived risk, reduced investment, and more difficult access to insurance or counterparties. Compromised keys, signers, and infrastructure accounted for 88.3% of the roughly $764 million stolen during Q2 2026.
Institutional due diligence is beginning to include signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits, according to the report. Abraxas Capital now explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies.
The shift has also appeared in regulatory and industry scrutiny. In a July 10 Cointelegraph report, BitGo Chief Operating Officer Jody Mettler said institutional clients had begun asking more detailed questions about custody providers' access controls, incident response, and business continuity as European regulators examined operational resilience under the Digital Operational Resilience Act (DORA).
Hacken said 14 projects exploited in Q2 2026 had previously been audited. However, most losses stemmed from areas outside the scope of conventional smart contract reviews. The affected surfaces included signer devices, bridge validators, backend infrastructure, admin keys, and older contracts that remained live despite being deprecated.
What did Hacken's Q2 2026 report find about third-party monitoring in crypto projects?
Hacken's Q2 2026 Security & Compliance Report found that only 9% of 1,427 tracked crypto projects had third-party monitoring, while 4% combined monitoring with an active bug bounty and a security audit. The report covered projects with market caps above $1 million listed across the top 50 centralized exchanges by CoinGecko Trust Score.
Why are institutional investors looking beyond smart contract audits?
Institutional investors are looking beyond smart contract audits because traditional trust signals such as prior audits and operating history failed to predict which crypto projects would be exploited in Q2 2026. Compromised keys, signers, and infrastructure accounted for 88.3% of roughly $764 million stolen during the quarter, and 14 exploited projects had previously been audited, according to Hacken.
How has institutional due diligence for crypto projects changed?
Institutional due diligence now includes signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. Abraxas Capital explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies, according to Hacken's Q2 2026 report.
Related News
Cregis CEO on MiCA Impact and Institutional Digital Asset Infrastructure
KOSPI Stocks Forecast to Trade Sideways Through Year-End Amid Credit Concerns
Strategy Rebuilds $3B Reserve but Leaves Bitcoin Buy-Sell Rules Undefined
Big Tech Stocks Face AI Spending Scrutiny as Earnings Approach