Key facts
- Institutional investors are moving beyond traditional smart contract audits for crypto due diligence.
- Operational failures, including compromised keys and infrastructure, accounted for 88.3% of crypto losses in Q2 2026.
- A Hacken report found only 9% of tracked projects utilized third-party monitoring.
- Due diligence now emphasizes continuous monitoring, signer controls, incident readiness, and collateral backing.
- 14 audited projects were exploited in the second quarter, highlighting the limitations of static audits.
Institutional investors are increasingly prioritizing continuous monitoring, signer controls, and incident readiness over traditional smart contract audits when assessing crypto projects, according to a report by Hacken. The shift comes as operational failures, rather than smart contract vulnerabilities, have been identified as the primary cause of recent crypto losses.
Hacken's Q2 2026 Security & Compliance Report revealed that only 9% of 1,427 tracked projects had third-party monitoring, with a mere 4% combining monitoring with bug bounties and security audits. The report highlighted that compromised keys, signers, and infrastructure were responsible for 88.3% of the approximately $764 million stolen during the quarter. Projects failing to demonstrate ongoing operational security may face increased perceived risk, reduced investment, and greater difficulty accessing insurance or counterparties.
Federico Bagiotti, group head of risk management at Abraxas Capital, stated that inadequate security relative to the capital at risk was a frequent reason for rejecting potential positions. Rajeev Bamra, Moody’s Ratings’ head of digital economy strategy, emphasized that operational resilience has become the practical lens for evaluating security, compliance, and governance.
Institutional due diligence is now incorporating checks on signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. Abraxas Capital specifically screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-verifier dependencies. This trend is also reflected in regulatory scrutiny, with European regulators examining operational resilience under the Digital Operational Resilience Act (DORA), prompting custody providers to address detailed client questions on access controls and business continuity.
Despite 14 audited projects being exploited in the second quarter, the majority of losses originated from areas outside the scope of typical smart contract reviews, including signer devices, bridge validators, backend infrastructure, and deprecated contracts. The Hacken dataset included projects with market caps above $1 million, excluding wrapped assets, stablecoins, and tokenized real-world assets, relying on publicly observable controls.