Crypto institutions look beyond audits as trust signals falter: Hacken

Crypto institutions look beyond audits as trust signals falter: Hacken img1
Spread the love

Written by Ezra Reguerrastaff writerReviewed by Yohan Yunstaff editor

Written by Ezra Reguerrastaff writer

Reviewed by Yohan Yunstaff editor

Crypto institutions look beyond audits as trust signals falter: Hacken

Latest NewsPublishedJul 20, 2026

Institutional due diligence is shifting toward continuous monitoring, signer controls and incident readiness after operational failures accounted for most crypto losses.

Institutional investors are looking beyond smart contract audits after traditional trust signals such as prior audits and operating history failed to predict which crypto projects would be exploited, as reported by Hacken.

In its Q2 2026 Security & Compliance Report, Hacken stated that only 9% of 1,427 tracked projects had third-party monitoring, while 4% combined monitoring with an active bug bounty and a security audit. The report highlighted that compromised keys, signers and infrastructure accounted for 88.3% of the roughly $764 million stolen during the quarter. 

Hacken stated projects unable to provide ongoing evidence of operational security may face higher perceived risk, reduced investment and more difficult access to insurance or counterparties. 

Contributors to the report included Federico Bagiotti, group head of risk management at Abraxas Capital, who stated “inadequate security relative to the capital at risk” was the signal that most often led the firm to reject an otherwise attractive position. Rajeev Bamra, Moody’s Ratings’ head of digital economy strategy, stated that operational resilience had become “the practical lens” through which institutions evaluated security, compliance and governance.

Security controls among those reviewed. Source: Hacken

Operational security becomes an allocation test

The report stated institutional due diligence is beginning to include signer-set changes, collateral backing, third-party dependencies, incident-response readiness and the scope and recency of audits. Abraxas stated it now explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls and single-key or single-verifier dependencies.

The shift has also appeared in regulatory and industry scrutiny. In a July 10 Cointelegraph report, BitGo Chief Operating Officer Jody Mettler stated institutional clients had begun asking more detailed questions about custody providers’ access controls, incident response and business continuity as European regulators examined operational resilience under the Digital Operational Resilience Act (DORA).

Related: Crypto hacks fell 47% in H1 but ecosystem is no safer: CertiK

Hacken stated 14 projects exploited in the second quarter had previously been audited. nevertheless, most losses stemmed from areas outside the scope of conventional smart contract reviews. The affected surfaces included signer devices, bridge validators, backend infrastructure, admin keys and older contracts that remained live despite being deprecated. 

The dataset covered 1,427 projects with market caps above $1 million, drawn from assets listed across the top 50 centralized exchanges by CoinGecko Trust Score. Hacken excluded wrapped assets, stablecoins and tokenized real-world assets. Its data relied on publicly observable and disclosed controls, which means that private arrangements may not be captured. 

Magazine: Ethereum’s EEZ could pull other blockchains into its orbit

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

  • Security
  • Hacks
  • Hackers
  • Cybersecurity
  • Blockchain

More on the subject

Hyperliquid sets 500,000 HYPE stake for permissionless prediction market deployers



12 hours ago

Ezra Reguerra

News Brief

South Korea eyes September launch for second phase of CBDC pilot: Report



17 hours ago

Yohan Yun

News Brief

Cardano activates van Rossem hard fork



20 hours ago

Felix Ng

News Brief

Hyperliquid sets 500,000 HYPE stake for permissionless prediction market deployers



12 hours ago

Ezra Reguerra

News Brief

South Korea eyes September launch for second phase of CBDC pilot: Report



17 hours ago

Yohan Yun

News Brief

Cardano activates van Rossem hard fork



20 hours ago

Felix Ng

News Brief


💡 A Greener Way to Earn: Looking for a smarter, more sustainable way to earn and mining crypto? EcoPool Network is a cloud-based mining pool that does the heavy lifting on remote servers — so you earn rewards around the clock without worrying about overheating hardware or sky-high electricity bills. It’s lightweight, battery-friendly, and built for everyday users. Download EcoPool now and start mining & earning smarter today.

Spread the love

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these