Crypto institutions look beyond audits as trust signals falter: HackenInstitutional due diligence is shifting toward continuous monitoring, signer controls and incident readiness after operational failures accounted for most crypto losses.
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-assisted summary based on the linked source. Verify market-moving details at the original publisher before acting.
According to Hacken's Q2 2026 Security & Compliance Report, institutional investors in crypto are increasingly looking beyond traditional trust signals like prior smart contract audits and operating history, which have proven insufficient to predict project exploits. The report tracked 1,427 projects and found that only 9% had third-party continuous monitoring, and just 4% combined this monitoring with bug bounties and security audits. Most notably, the majority of crypto losses during the quarter—about $764 million stolen—were due to compromised keys, signers, and infrastructure, which traditional audits typically do not cover.
Hacken emphasized that projects unable to demonstrate ongoing operational security might face heightened risk perception, reduced investment opportunities, and difficulty accessing insurance or counterparties. Contributors from institutional firms echoed this theme; Federico Bagiotti of Abraxas Capital indicated that inadequate security in relation to the capital at risk often led his firm to reject investment opportunities. Rajeev Bamra of Moody’s Ratings highlighted operational resilience as the critical factor through which institutions now assess security, compliance, and governance.
The report also detailed how institutional due diligence is evolving to assess multiple operational factors beyond audits, including signer-set changes, collateral backing, third-party dependencies, and incident-response readiness. Abraxas specifically screens for controls such as timelocks, withdrawal-address whitelisting, multiparty controls, and avoidance of single-key dependencies. This shift toward operational security scrutiny is mirrored in regulatory developments like Europe’s Digital Operational Resilience Act (DORA), which has prompted institutional clients to ask more rigorous questions about custody providers' controls and business continuity.
Hacken noted that 14 audited projects were exploited in Q2, but the compromises mostly occurred in areas outside conventional smart contract audits, such as signer devices, backend infrastructure, admin keys, and legacy contracts still active despite being deprecated. Their dataset included projects with market caps above $1 million listed across the top 50 centralized exchanges, excluding wrapped assets, stablecoins, and tokenized real-world assets. The report’s findings are based on publicly observable controls, with private arrangements potentially not reflected. Overall, Hacken’s analysis underscores a critical industry trend toward continuous monitoring and enhanced operational controls as essential to mitigating risks beyond what traditional audits address.