Crypto Institutions Prioritize Operational Security Amid Audit Shortcomings
Institutional investors are increasingly looking beyond traditional smart contract audits as primary indicators of trust in crypto projects. A report by Hacken indicates that prior audits and operational history have not consistently predicted vulnerability to exploits.
Hacken’s Q2 2026 Security & Compliance Report revealed that only 9% of 1,427 tracked projects utilized third-party monitoring. Only 4% combined monitoring with an active bug bounty program and a security audit. The report detailed that compromised keys, signers, and infrastructure were responsible for 88.3% of the approximately $764 million in stolen funds during the quarter.
Shifting Institutional Due Diligence
The report suggests that projects unable to demonstrate ongoing operational security may face heightened perceived risk, reduced investment prospects, and difficulties in securing insurance or engaging with counterparties. Federico Bagiotti, group head of risk management at Abraxas Capital, noted that inadequate security relative to the capital at risk frequently led his firm to reject otherwise attractive positions. Rajeev Bamra, Moody’s Ratings’ head of digital economy strategy, stated that operational resilience has become a crucial criterion for institutions evaluating security, compliance, and governance.
Beyond Smart Contract Audits
Institutional due diligence processes are evolving to include assessments of signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. Abraxas now specifically screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies. This shift is also evident in regulatory and industry scrutiny, with European regulators examining operational resilience under the Digital Operational Resilience Act (DORA).
Hacken identified 14 projects exploited in Q2 that had undergone previous audits. However, the majority of losses originated from areas outside the typical scope of smart contract reviews, including signer devices, bridge validators, backend infrastructure, admin keys, and deprecated older contracts that remained active. The report’s dataset encompassed 1,427 projects with market capitalizations exceeding $1 million, listed on the top 50 centralized exchanges. Wrapped assets, stablecoins, and tokenized real-world assets were excluded from the analysis, which relied on publicly observable and disclosed controls.