The landscape of institutional investment in cryptocurrencies is undergoing a significant transformation, as traditional trust signals such as smart contract audits and operational history prove insufficient in preventing security breaches. According to a recent report by blockchain security firm Hacken, institutional investors are now looking beyond audits toward continuous monitoring, signer controls, and incident readiness. This shift comes in the wake of a quarter where operational failures dominated the crypto loss narrative.
Hacken's Q2 2026 Security & Compliance Report analyzed 1,427 projects with market capitalizations above $1 million, drawn from assets listed on the top 50 centralized exchanges by CoinGecko Trust Score. The findings underscore a stark reality: only 9% of these projects had third-party monitoring, while a mere 4% combined monitoring with an active bug bounty and a security audit. The report highlights that compromised keys, signers, and infrastructure accounted for 88.3% of the roughly $764 million stolen during the quarter. This statistic is a wake-up call for the industry, indicating that the most significant threats are not in smart contract code but in operational and administrative layers.
Operational security becomes a core due diligence criterion
Institutional due diligence is now incorporating a broader set of metrics. According to the report, factors such as signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits are becoming standard screens. Abraxas Capital, a major crypto investment firm, explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies. Federico Bagiotti, group head of risk management at Abraxas Capital, stated that "inadequate security relative to the capital at risk" was the signal that most often led the firm to reject an otherwise attractive position.
Rajeev Bamra, Moody's Ratings' head of digital economy strategy, emphasized that operational resilience has become "the practical lens" through which institutions evaluate security, compliance, and governance. This shift reflects a broader trend among institutional investors who are increasingly risk-averse and demand concrete, verifiable evidence of security practices rather than relying on static audit reports.
Regulatory pressures accelerate the shift
The move toward operational security is also being driven by regulatory developments. In Europe, the Digital Operational Resilience Act (DORA) has set new standards for financial institutions, including those in the crypto space. According to a July 10 Cointelegraph report, BitGo Chief Operating Officer Jody Mettler noted that institutional clients have begun asking more detailed questions about custody providers' access controls, incident response, and business continuity. DORA requires firms to demonstrate robust operational resilience, including continuous monitoring and incident management. This regulatory pressure is likely to push more crypto projects to adopt the kind of ongoing security measures that Hacken's report emphasizes.
Hacken's data shows that 14 projects exploited in the second quarter had previously been audited. However, most losses stemmed from areas outside the scope of conventional smart contract reviews. The affected surfaces included signer devices, bridge validators, backend infrastructure, admin keys, and older contracts that remained live despite being deprecated. This highlights a critical gap: audits are point-in-time assessments and cannot capture the evolving threats that arise from operational practices or the accumulation of technical debt.
Key findings from the report
Among the 1,427 projects analyzed, the report found that only a fraction had robust security measures in place. The 9% with third-party monitoring and 4% combining monitoring, bug bounty, and audit represent a severe underinvestment in operational security. The report also noted that the dataset, which excluded wrapped assets, stablecoins, and tokenized real-world assets, relied on publicly observable and disclosed controls. This means that private arrangements, such as behind-the-scenes security protocols or insurance policies, may not be captured. Nevertheless, the findings point to systemic weaknesses in the crypto ecosystem.
To understand the magnitude of the problem, consider that $764 million in losses occurred in just three months. This is not an insignificant amount, and it underscores the urgency for projects to adopt continuous security practices. The report suggests that projects unable to provide ongoing evidence of operational security may face higher perceived risk, reduced investment, and more difficult access to insurance or counterparties.
Detailed analysis of operational failures
Operational failures encompass a range of issues, from compromised private keys to poorly maintained infrastructure. For example, when a project's admin keys are stored on a single device that gets compromised, an audit of the smart contract would not have prevented the theft. Similarly, bridge validators that are not properly secured can lead to massive losses. The report's emphasis on signer controls is particularly relevant, as many decentralized finance (DeFi) protocols rely on multi-sig wallets or governance mechanisms that can be exploited if not properly managed.
The report also highlights the importance of incident-response readiness. Having a plan in place to quickly respond to a breach can mitigate losses and protect investor confidence. Yet few projects seem to prioritize this. The lack of bug bounties is another concern, as these programs can incentivize white-hat hackers to find vulnerabilities before malicious actors do.
Background: The evolution of crypto security
The crypto industry has come a long way from the early days when exchanges were frequently hacked and user funds disappeared. With the growth of institutional involvement, security practices have evolved. Initially, smart contract audits were the gold standard. However, as the market has matured, it has become clear that audits alone are insufficient. The collapse of FTX, though not a technical hack, illustrated how operational failures—specifically poor governance and misuse of customer funds—could cause catastrophic losses.
Regulators around the world have taken notice. The European Union's Markets in Crypto-Assets (MiCA) regulation, which came into effect in 2024 in parts, includes requirements for operational resilience. Similarly, the U.S. Securities and Exchange Commission (SEC) has scrutinized crypto projects for their security practices. The pressure is mounting for projects to go beyond audits and adopt continuous monitoring systems akin to those used in traditional finance.
Hacken's report is part of a growing body of evidence that the crypto industry must prioritize operational security. Other security firms, such as CertiK, have also noted that while hack volumes may have dropped in the first half of 2026, the ecosystem is not necessarily safer. In fact, the types of attacks are shifting, and the sophistication of attackers is increasing.
Practical steps for projects
What can crypto projects do to meet institutional expectations? First, they should implement multi-party controls and timelocks on critical functions. Second, they should conduct regular penetration testing and vulnerability assessments beyond the scope of standard audits. Third, they should establish incident response teams and run tabletop exercises. Fourth, they should consider insurance coverage that requires proof of ongoing security measures.
For investors, the message is clear: due diligence must go beyond reading an audit report. They should demand evidence of continuous monitoring, signer set management, and third-party dependencies. They should also assess the quality of the team's security culture and their track record in responding to incidents.
The Hacken report concludes with a call to action for the industry to embrace a culture of security that is proactive rather than reactive. As institutional money flows deeper into crypto, those projects that invest in operational security will be best positioned to attract and retain sophisticated investors.
Source: Cointelegraph News