Key facts
- Institutional investors are shifting focus from traditional audits to operational security in crypto.
- Hacken's report indicates a low percentage of crypto projects have comprehensive security monitoring and bug bounties.
- Compromised keys and infrastructure were the primary cause of crypto hacks in Q2, resulting in significant losses.
- Inadequate operational security can lead to higher perceived risk, reduced investment, and difficulty accessing insurance.
- Key areas of institutional due diligence now include signer-set changes, incident response, and third-party dependencies.
Institutional investors in the cryptocurrency space are increasingly prioritizing operational security over traditional trust signals like smart contract audits, according to a report by Hacken. The firm's Q2 2026 Security & Compliance Report found that only 9% of 1,427 tracked projects had third-party monitoring, with an even smaller percentage combining this with active bug bounties and security audits.
Hacken highlighted that compromised keys, signers, and infrastructure were responsible for 88.3% of the approximately $764 million stolen during the second quarter. Projects that cannot provide ongoing evidence of operational security may face heightened perceived risk, leading to reduced investment and more challenging access to insurance or counterparties.
Federico Bagiotti, group head of risk management at Abraxas Capital, stated that inadequate security relative to the capital at risk was a frequent reason for rejecting attractive positions. Rajeev Bamra, Moody’s Ratings’ head of digital economy strategy, emphasized that operational resilience has become the primary lens through which institutions evaluate security, compliance, and governance.
Institutional due diligence is now incorporating checks on signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. Abraxas specifically screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies. This shift is also reflected in regulatory scrutiny, with European regulators examining operational resilience under the Digital Operational Resilience Act (DORA), prompting institutional clients to ask more detailed questions about custody providers' access controls and business continuity.