HomeAll NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Crypto institutions prioritize operational security over audits: Hacken

Created at 22 Jul · 12:16 PM1 source↑ Market-relevant
IN SHORT

Institutional investors are increasingly scrutinizing operational security, including signer-set changes and incident response readiness, over traditional trust signals like prior audits, according to Hacken's Q2 2026 Security & Compliance Report. Compromised keys and infrastructure led to $764 million in losses.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

9%projects with third-party monitoring
4%projects with monitoring, bug bounty, and audit
$764 millionstolen in Q2 due to compromised keys/infrastructure
88.3%losses from compromised keys, signers, and infrastructure
1,427tracked projects in Hacken's report
14exploited projects in Q2 had prior audits

Who's Involved

Hacken
security and compliance firm that published the Q2 2026 report
Federico Bagiotti
group head of risk management at Abraxas Capital
Rajeev Bamra
Moody’s Ratings’ head of digital economy strategy
Jody Mettler
Chief Operating Officer at BitGo

↳ Why This Matters

The evolving due diligence standards signal a maturing crypto market where operational robustness is becoming as critical as code security, potentially impacting investment flows and the perceived risk of digital asset platforms.

Key facts

  • Institutional investors are shifting focus from traditional audits to operational security in crypto.
  • Hacken's report indicates a low percentage of crypto projects have comprehensive security monitoring and bug bounties.
  • Compromised keys and infrastructure were the primary cause of crypto hacks in Q2, resulting in significant losses.
  • Inadequate operational security can lead to higher perceived risk, reduced investment, and difficulty accessing insurance.
  • Key areas of institutional due diligence now include signer-set changes, incident response, and third-party dependencies.

Institutional investors in the cryptocurrency space are increasingly prioritizing operational security over traditional trust signals like smart contract audits, according to a report by Hacken. The firm's Q2 2026 Security & Compliance Report found that only 9% of 1,427 tracked projects had third-party monitoring, with an even smaller percentage combining this with active bug bounties and security audits.

Hacken highlighted that compromised keys, signers, and infrastructure were responsible for 88.3% of the approximately $764 million stolen during the second quarter. Projects that cannot provide ongoing evidence of operational security may face heightened perceived risk, leading to reduced investment and more challenging access to insurance or counterparties.

Federico Bagiotti, group head of risk management at Abraxas Capital, stated that inadequate security relative to the capital at risk was a frequent reason for rejecting attractive positions. Rajeev Bamra, Moody’s Ratings’ head of digital economy strategy, emphasized that operational resilience has become the primary lens through which institutions evaluate security, compliance, and governance.

Institutional due diligence is now incorporating checks on signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. Abraxas specifically screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies. This shift is also reflected in regulatory scrutiny, with European regulators examining operational resilience under the Digital Operational Resilience Act (DORA), prompting institutional clients to ask more detailed questions about custody providers' access controls and business continuity.

Frequently asked questions

The report indicates that compromised keys, signers, and infrastructure were the primary cause of crypto hacks in the second quarter.

Institutional due diligence is now focusing more on operational security aspects like signer-set changes, incident response, and third-party dependencies, rather than solely relying on smart contract audits.

Approximately $764 million was stolen in crypto hacks during the second quarter.

Only 9% of the 1,427 tracked projects had third-party monitoring, and 4% combined monitoring with an active bug bounty and a security audit.

What Happens Next

01Projects may need to demonstrate enhanced operational security to attract institutional investment.
02Regulators are expected to continue scrutinizing operational resilience in the digital asset sector.
03Custody providers will likely face increased demand for detailed information on access controls and business continuity.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Institutional investors are looking beyond traditional trust signals like prior audits.
Hacken's Q2 2026 Security & Compliance Report found only 9% of tracked projects had third-party monitoring.
Compromised keys, signers, and infrastructure accounted for 88.3% of $764 million stolen in Q2.
Projects lacking ongoing operational security evidence may face higher perceived risk and reduced investment.
Moody's Ratings noted operational resilience as a key evaluation lens for institutions.
Institutional due diligence now includes signer-set changes, collateral backing, and incident-response readiness.
BitGo reported institutional clients are asking more detailed questions about custody providers' controls.
projects exploited in Q2 had prior audits, but losses stemmed from areas outside smart contract reviews.

Sources

T1
Crypto institutions look beyond audits as trust signals falter: HackenCointelegraph

Related Stories

Midnight token rebounds 19% after Wanchain bridge hack, Hoskinson calls for ZK revamp
22 Jul · 11:56 AM
South Korea Crypto Volumes Shrink as Retail Investors Shift to Stocks
22 Jul · 10:56 AM
Balance Coin Crashes 99% After $915K Exploit
22 Jul · 3:31 AM
S&P Dow Jones & Pantera Exclude Bitcoin, XRP From New Crypto Index
22 Jul · 7:41 AM
Russia Passes Landmark Crypto Law, Enabling State-Supervised Sanctioned Trade
21 Jul · 1:21 PM