
Institutional due diligence is moving beyond audits after 88.3% of Q2's $764M in crypto losses stemmed from operational failures, Hacken reports.
Institutional investors are moving beyond smart contract audits after traditional trust signals failed to predict which crypto projects would be exploited, according to Hacken.
The security firm's Q2 2026 Security & Compliance Report tracked 1,427 projects. Only 9% had third-party monitoring in place. Just 4% combined monitoring with an active bug bounty and a security audit. The report found that compromised keys, signer devices, and infrastructure accounted for 88.3% of the roughly $764 million stolen during the quarter.
Hacken said projects that cannot show ongoing evidence of operational security may face higher perceived risk, reduced investment, and harder access to insurance or counterparties.
Federico Bagiotti, group head of risk management at Abraxas Capital, contributed to the report.
Rajeev Bamra, Moody's Ratings' head of digital economy strategy, said operational security had become the practical lens through which institutions evaluate security, compliance and governance. Moody's, which rates digital assets through that group, carries an AlphaScala Alpha Score of 57 (Moderate) in the Financials sector. MCO stock page
The report said institutional due diligence is beginning to include signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. Abraxas now explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies.
Regulatory and industry scrutiny is also shifting. In a July 10 Cointelegraph report, BitGo Chief Operating Officer Jody Mettler said institutional clients had started asking more detailed questions about custody providers' access controls and incident response as European regulators examined operational security under the Digital Operational Resilience Act.
Hacken said 14 projects exploited in the second quarter had previously been audited. Most losses stemmed from areas outside conventional smart contract reviews: signer devices, bridge validators, backend infrastructure, admin keys, and older contracts that remained live despite being deprecated.
The dataset covered 1,427 projects with market caps above $1 million, drawn from assets listed across the top 50 centralized exchanges by CoinGecko Trust Score. Hacken excluded wrapped assets, stablecoins, and tokenized real-world assets. Its data relied on publicly observable and disclosed controls, which means private arrangements may not be captured.
For broader context on crypto market trends, see crypto market analysis.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.