Fintech & Crypto Alerts · Cameron Ellis · 20 July 2026

Crypto institutions look beyond audits as trust signals fade

Crypto institutions look beyond audits as trust signals fade

Crypto institutions look beyond smart contract audits after traditional trust signals failed to predict exploits, according to Hacken's Q2 2026 Security & Compliance Report. Compromised keys, signers and infrastructure drove 88.3% of roughly $764 million stolen in the quarter, pushing due diligence toward continuous monitoring, signer controls and incident readiness.

Key Takeaways

Why are crypto institutions looking beyond audits?

Institutional investors are rethinking what counts as a credible trust signal in digital assets. Prior audits and operating history failed to flag which projects would be exploited, Cointelegraph reported on Hacken's findings.

That shift matters for anyone following Fintech & Crypto Alerts coverage: a clean audit stamp no longer equals institutional comfort. Capital at risk is colliding with thin operational defenses, and allocators are adjusting screens accordingly.

What does Hacken's Q2 2026 report show?

Hacken's Security & Compliance Report tracked 1,427 projects with market caps above $1 million, drawn from assets listed across the top 50 centralized exchanges by CoinGecko Trust Score. Wrapped assets, stablecoins and tokenized real-world assets were excluded.

Only 9% had third-party monitoring. Just 4% combined monitoring with an active bug bounty and a security audit. Roughly $764 million was stolen in the quarter, and 88.3% of those losses stemmed from compromised keys, signers and infrastructure.

Fourteen projects exploited in Q2 had previously been audited. Most damage came from signer devices, bridge validators, backend infrastructure, admin keys and older contracts that stayed live after deprecation—areas outside conventional smart contract review scope.

Hacken relied on publicly observable and disclosed controls, so private arrangements may not appear in the dataset.

How is institutional due diligence changing?

Due diligence is expanding to signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. Abraxas Capital now screens for timelocks, withdrawal-address whitelisting, multiparty controls and single-key or single-verifier dependencies.

Federico Bagiotti, group head of risk management at Abraxas Capital, said "inadequate security relative to the capital at risk" most often led the firm to reject an otherwise attractive position. Rajeev Bamra, Moody's Ratings head of digital economy strategy, said operational resilience had become "the practical lens" for security, compliance and governance.

European scrutiny under the Digital Operational Resilience Act (DORA) is reinforcing the same theme. BitGo COO Jody Mettler said institutional clients are asking deeper questions about custody access controls, incident response and business continuity.

What happens to projects without ongoing security?

Hacken warned that projects unable to show ongoing evidence of operational security may face higher perceived risk, reduced investment and harder access to insurance or counterparties. As crypto institutions look beyond checklist audits, continuous monitoring and signer discipline are becoming allocation tests—not optional extras.

Audits still matter for code quality. They no longer stand alone as proof that a protocol can protect institutional capital when keys, infrastructure and admin paths fail.

← Open in blast feed