Audits Get an F in Stopping Hacks — Institutions Hand Out Pop Quizzes Instead 📝
Institutional crypto investors are moving past smart-contract audits as a primary trust signal after audits and operating histories repeatedly failed to flag projects that were later exploited, according to cybersecurity firm Hacken's Q2 2026 Security & Compliance Report. Hacken found that only 9% of 1,427 tracked projects had third-party monitoring in place, while 4% combined monitoring with an active bug bounty and a security audit. Compromised keys, signers and infrastructure accounted for 88.3% of the roughly $764 million stolen during the quarter. Hacken said projects unable to provide ongoing evidence of operational security may face higher perceived risk, reduced investment and more difficult access to insurance or counterparties.
The report's contributors framed operational resilience as the new benchmark for institutional due diligence. Federico Bagiotti, group head of risk management at Abraxas Capital, said "inadequate security relative to the capital at risk" was the signal that most often led the firm to reject an otherwise attractive position. Rajeev Bamra, Moody's Ratings' head of digital economy strategy, said operational resilience had become "the practical lens" through which institutions evaluated security, compliance and governance. Abraxas said it now explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls and single-key or single-verifier dependencies.
Regulatory and industry scrutiny has moved in the same direction. In a July 10 Cointelegraph report, BitGo Chief Operating Officer Jody Mettler said institutional clients had begun asking more detailed questions about custody providers' access controls, incident response and business continuity as European regulators examined operational resilience under the Digital Operational Resilience Act (DORA). Hacken said 14 projects exploited in the second quarter had previously been audited, and that most losses stemmed from areas outside the scope of conventional smart-contract reviews, including signer devices, bridge validators, backend infrastructure, admin keys and older contracts that remained live despite being deprecated.
Hacken said institutional due diligence is beginning to include signer-set changes, collateral backing, third-party dependencies, incident-response readiness and the scope and recency of audits. The dataset covered 1,427 projects with market caps above $1 million, drawn from assets listed across the top 50 centralized exchanges by CoinGecko Trust Score. Hacken excluded wrapped assets, stablecoins and tokenized real-world assets, and noted its data relied on publicly observable and disclosed controls, meaning private arrangements may not be captured.
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.