According to Hacken, institutional investors are moving beyond shrewd contract audits after conventional trust signals such as past audits and operational history failed to predict which crypto projects would be used.
In its Q2 2026 Security and Compliance Report, Hacken found that only 9% of the 1,427 projects tracked were monitored by third parties, while 4% combined monitoring with busy bug bounty and security auditing. The report highlighted that compromised keys, signers and infrastructure accounted for 88.3% of the approximately $764 million stolen in the quarter.
Hacken said projects that cannot provide continuous evidence of operational security may have greater perceived risk, reduced investment and more challenging access to insurance or contractors.
The report’s authors included Federico Bagiotti, head of the risk management group at Abraxas Capital, who said that “inadequate security in relation to the capital at risk” was the signal that most often led a company to reject an otherwise attractive position. Rajeev Bamra, head of digital economy strategy at Moody’s Ratings, said operational resilience has become a “practical lens” through which institutions assess security, compliance and governance.
Safety checks among those reviewed. source: Hacken
Operational security becomes an allocation test
The report indicates that institutional due diligence is beginning to take into account changes in the composition of signatories, safeguards in the form of safeguards, dependencies on third parties, readiness to respond to incidents, and the scope and timeliness of audits. Abraxas said it now explicitly checks for time locks, payout address whitelisting, multi-party checks, and single-key or single-verifier dependencies.
This change also appeared in regulatory and industry analysis. In a July 10 Cointelegraph report, BitGo’s chief operating officer, Jody Mettler, said institutional clients began asking more specific questions about custody providers’ access controls, incident response and business continuity as European regulators examined operational resiliency under the Digital Operational Resilience Act (DORA).
Related: Cryptocurrency hacks dropped by 47% in the first half of the year, but the ecosystem is no safer: CertiK
Hacken said 14 projects used in the second quarter had previously been audited. However, most of the losses resulted from areas outside the scope of conventional shrewd contract reviews. Affected surfaces included signing devices, bridge validators, back-end infrastructure, administrative keys, and legacy contracts that remained busy despite their obsolescence.
The dataset included 1,427 projects with a market capitalization above $1 million, sampled from assets listed on the 50 largest centralized exchanges according to CoinGecko Trust Score. Hacken excluded wrapped assets, stablecoins and tokenized real-world assets. Its data relied on publicly observable and disclosed controls, meaning private findings may not be captured.
Warehouse: Ethereum’s WSE may drag other blockchains into its orbit
