Hacken: Institutions Move Beyond Audits After $764M Q2 Crypto Exploits

Institutional investors are looking beyond smart contract audits after traditional trust signals such as prior audits and operating history failed to predict which crypto projects would be exploited in Q2 2026, according to Hacken. The shift follows a quarter in which compromised keys, signers, and infrastructure accounted for 88.3% of roughly $764 million stolen, as detailed in Hacken's Q2 2026 Security & Compliance Report. Federico Bagiotti, group head of risk management at Abraxas Capital, said "inadequate security relative to the capital at risk" was the signal that most often led the firm to reject an otherwise attractive position, while Rajeev Bamra, Moody's Ratings' head of digital economy strategy, noted that operational resilience had become "the practical lens" through which institutions evaluated security, compliance, and governance.

Hacken Q2 2026 Report Reveals Low Monitoring Adoption

Hacken's Q2 2026 Security & Compliance Report tracked 1,427 crypto projects with market caps above $1 million. The report found that only 9% of these projects had third-party monitoring, while 4% combined monitoring with an active bug bounty and a security audit. The dataset covered assets listed across the top 50 centralized exchanges by CoinGecko Trust Score, excluding wrapped assets, stablecoins, and tokenized real-world assets. Hacken noted that its data relied on publicly observable and disclosed controls, meaning private arrangements may not be captured.

The report stated that projects unable to provide ongoing evidence of operational security may face higher perceived risk, reduced investment, and more difficult access to insurance or counterparties. Compromised keys, signers, and infrastructure accounted for 88.3% of the roughly $764 million stolen during Q2 2026.

Institutional Due Diligence Expands to Operational Controls

Institutional due diligence is beginning to include signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits, according to the report. Abraxas Capital now explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies.

The shift has also appeared in regulatory and industry scrutiny. In a July 10 Cointelegraph report, BitGo Chief Operating Officer Jody Mettler said institutional clients had begun asking more detailed questions about custody providers' access controls, incident response, and business continuity as European regulators examined operational resilience under the Digital Operational Resilience Act (DORA).

Audited Projects Exploited Through Infrastructure Weaknesses

Hacken said 14 projects exploited in Q2 2026 had previously been audited. However, most losses stemmed from areas outside the scope of conventional smart contract reviews. The affected surfaces included signer devices, bridge validators, backend infrastructure, admin keys, and older contracts that remained live despite being deprecated.

FAQ

What did Hacken's Q2 2026 report find about third-party monitoring in crypto projects?

Hacken's Q2 2026 Security & Compliance Report found that only 9% of 1,427 tracked crypto projects had third-party monitoring, while 4% combined monitoring with an active bug bounty and a security audit. The report covered projects with market caps above $1 million listed across the top 50 centralized exchanges by CoinGecko Trust Score.

Why are institutional investors looking beyond smart contract audits?

Institutional investors are looking beyond smart contract audits because traditional trust signals such as prior audits and operating history failed to predict which crypto projects would be exploited in Q2 2026. Compromised keys, signers, and infrastructure accounted for 88.3% of roughly $764 million stolen during the quarter, and 14 exploited projects had previously been audited, according to Hacken.

How has institutional due diligence for crypto projects changed?

Institutional due diligence now includes signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. Abraxas Capital explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies, according to Hacken's Q2 2026 report.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments