Institutional investors are moving past smart contract audits as the primary measure of crypto security, after conventional trust signals consistently failed to identify which projects would be exploited, according to a new report from blockchain security firm Hacken.
Most Projects Lack Basic Monitoring
Hacken’s Q2 2026 Security and Compliance Report, which covered 1,427 projects with market capitalizations above $1 million drawn from assets listed across the top 50 centralized exchanges by CoinGecko Trust Score, found that only 9% of those projects had third-party monitoring in place. Just 4% combined monitoring with both an active bug bounty program and a security audit.
Compromised keys, signers and infrastructure accounted for 88.3% of the approximately $764 million stolen across the quarter. Hacken also noted that 14 projects exploited during the period had previously been audited, with most losses originating from areas entirely outside the scope of standard smart contract reviews. Affected attack surfaces included signer devices, bridge validators, backend infrastructure, admin keys and deprecated contracts that remained live.
The dataset excluded wrapped assets, stablecoins and tokenized real-world assets, and Hacken acknowledged that private security arrangements may not be captured since its data relied on publicly observable and disclosed controls.
Operational Security Becomes an Allocation Test
Hacken warned that projects unable to provide continuous evidence of operational security may face higher perceived risk, reduced investment and harder access to insurance or counterparties.
Federico Bagiotti, group head of risk management at Abraxas Capital, contributed to the report and said that ‘inadequate security relative to the capital at risk’ was the signal that most frequently caused his firm to reject an otherwise attractive position. Abraxas said it now explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls and single-key or single-verifier dependencies.
Rajeev Bamra, Moody’s Ratings head of digital economy strategy, said operational resilience had become ‘the practical lens’ through which institutions evaluate security, compliance and governance.
The report said institutional due diligence is beginning to include signer-set changes, collateral backing, third-party dependencies, incident-response readiness and the scope and recency of audits, marking a significant expansion beyond point-in-time code reviews.
Regulatory Pressure Reinforcing the Shift
The trend extends beyond private investment decisions. BitGo Chief Operating Officer Jody Mettler noted in a July 10 report that institutional clients had begun asking more detailed questions about custody providers’ access controls, incident response and business continuity, as European regulators examined operational resilience requirements under the Digital Operational Resilience Act (DORA).
The findings place direct pressure on crypto projects to demonstrate ongoing operational controls rather than point-in-time code certifications, as institutional capital increasingly treats security posture as a prerequisite rather than a checkbox.


