After years of relying on smart contract audits as a key “trust signal,” institutional investors are increasingly treating operational security as the real gatekeeper for allocating capital t
After years of relying on smart contract audits as a key “trust signal,” institutional investors are increasingly treating operational security as the real gatekeeper for allocating capital to crypto projects. Hacken’s Q2 2026 Security & Compliance Report argues that conventional review artifacts—such as third-party audits and a project’s operating history—have not consistently correlated with which systems end up being exploited.
In the quarter, Hacken tracked 1,427 crypto projects (with market caps above $1 million) and found that only a small fraction had meaningful layers of ongoing monitoring. At the same time, it attributes the majority of losses to compromise scenarios that traditional contract-level audits typically don’t cover, including keys, signers, and surrounding infrastructure. For risk teams, the takeaway is clear: due diligence is moving beyond code review toward evidence that controls are actively maintained and resilient.
Key takeaways
- Hacken reports just 9% of 1,427 tracked projects had third-party monitoring, and only 4% combined monitoring with both a bug bounty and a security audit.
- Across the quarter’s reported thefts of roughly $764 million, Hacken attributes 88.3% of losses to compromised keys, signers, and infrastructure.
- Operational security reviews are expanding to include signer-set changes, collateral backing, third-party dependencies, and incident-response readiness.
- Hacken says projects that cannot show ongoing evidence of operational security may face higher perceived risk, less investment interest, and harder access to insurance or counterparties.
Why audits are no longer enough
Hacken’s central argument is that the audit-centric approach doesn’t reliably predict whether a project will be exploited. According to the report, institutional confidence signals such as prior audits and operational history have not offered consistent protection against real-world compromise.
The report’s data helps explain why. Hacken notes that while 14 of the projects exploited in Q2 had previously undergone audits, the losses mostly came from attack surfaces beyond the typical scope of smart contract review. Those surfaces included signer devices, bridge validator components, backend infrastructure, admin keys, and “older” contracts that remained active even after being deprecated.
That distinction matters for investors because it reframes what “secure” means. An audited contract can still be vulnerable if the surrounding operational controls—key management, signing processes, administrative access, and supporting infrastructure—are weak, stale, or insufficiently monitored.
The monitoring gap highlights a control reality
Hacken’s review of 1,427 projects (based on assets listed across the top 50 centralized exchanges by CoinGecko Trust Score) is designed to capture observable and disclosed control setups. The methodology matters: Hacken’s dataset excludes wrapped assets, stablecoins, and tokenized real-world assets, and it relies on publicly observable arrangements—meaning private measures may not show up in the analysis.
Even with that limitation, the numbers point to a broad monitoring gap. Only 9% of tracked projects had third-party monitoring, and just 4% combined monitoring with an active bug bounty and a security audit. In practice, this suggests that most projects may lack layered external scrutiny that can detect or deter issues before attackers exploit weaknesses.
Hacken also flags a structural consequence for capital access: when projects cannot provide continuing evidence that security controls remain effective over time, they may be priced as higher risk. That can ripple outward into fewer investment opportunities and more difficult negotiations with counterparties and insurers.
Operational resilience reshapes due diligence
Hacken says institutional due diligence is broadening in ways that extend past contract correctness. Its report describes a shift toward checking not just “what was audited,” but how the system operates day to day.
Among the areas now being incorporated are signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. The emphasis on recency is particularly relevant: even a strong audit from the past may not reflect changes in infrastructure, control policies, governance, or integration dependencies.
One investor risk example comes from Abraxas Capital. In the report, Federico Bagiotti, group head of risk management at Abraxas Capital, is cited saying that “inadequate security relative to the capital at risk” was the factor that most often drove the firm to reject positions. The operational controls Abraxas reportedly screens for include timelocks, withdrawal-address whitelisting, multiparty controls, and avoiding reliance on a single key or single verifier.
Moody’s Ratings’ perspective adds another layer: Rajeev Bamra, head of digital economy strategy at Moody’s Ratings, is quoted in the report stating that operational resilience has become “the practical lens” institutions use to evaluate security, compliance, and governance. Taken together, these views suggest investors are trying to reduce uncertainty by focusing on how failures are prevented—or contained—rather than trusting a static snapshot of code review.
Regulators are also pushing the conversation toward resilience
The report’s narrative aligns with wider scrutiny of operational robustness in the custody and compliance stack. In a July 10 Cointelegraph report, BitGo Chief Operating Officer Jody Mettler said institutional clients had started asking more detailed questions about custody providers’ access controls, incident response, and business continuity, as European regulators examined operational resilience under the Digital Operational Resilience Act (DORA).
That regulatory pressure helps explain why audits alone are losing their predictive value. Key management, signing access, operational continuity, and incident workflows are not merely “best practices”—they are increasingly part of what regulators and risk committees expect to see operationalized.
Hacken’s findings reinforce that point. With 88.3% of the roughly $764 million stolen in Q2 traced to compromised keys, signers, and infrastructure, the industry’s focus on resilience moves closer to the areas where losses actually originate.
What readers should watch next
The next test for projects and investors will be whether security programs evolve from periodic audits into verifiable, continuously maintained controls—especially around signing authority, key custody, administrative access, and incident readiness. Hacken’s Q2 findings suggest that diligence will increasingly reward ongoing evidence, not just historical certifications, so investors should watch how quickly teams improve monitoring coverage and tighten operational guardrails as systems and dependencies change.
This article was originally published as Crypto Firms Move Past Audits as Trust Signals Weaken, Hacken Says on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.