Best Miami News connects businesses and publishers

collapse
Home / Daily News Analysis / Crypto institutions look beyond audits as trust signals falter: Hacken

Crypto institutions look beyond audits as trust signals falter: Hacken

Jul 25, 2026  Twila Rosenbaum 2 views
Crypto institutions look beyond audits as trust signals falter: Hacken

The landscape of institutional cryptocurrency investment is undergoing a fundamental shift in how security is evaluated. According to Hacken's Q2 2026 Security & Compliance Report, traditional trust signals such as prior smart contract audits and operating history are no longer sufficient to predict which projects will suffer exploits. Institutional due diligence is increasingly focusing on continuous monitoring, signer controls, and incident response preparedness.

The report, which tracked 1,427 projects with market caps above $1 million, revealed that only 9% of these projects had third-party monitoring in place. An even smaller fraction—just 4%—combined monitoring with an active bug bounty program and a security audit. This gap is particularly concerning given that compromised keys, signers, and infrastructure accounted for approximately 88.3% of the roughly $764 million stolen during the second quarter of 2026.

Hacken warned that projects unable to provide ongoing evidence of operational security may face higher perceived risk, reduced investment, and more difficult access to insurance or counterparties. This marks a departure from earlier periods when a single audit was often considered a sufficient endorsement of a project's security posture.

The Limitations of Traditional Audits

Smart contract audits have been a cornerstone of crypto security for years. They are designed to identify vulnerabilities in code before deployment. However, the Hacken report underscores that audits are not a panacea. Fourteen projects that were exploited in the second quarter had previously been audited. The losses stemmed from areas outside the scope of conventional smart contract reviews, including signer devices, bridge validators, backend infrastructure, admin keys, and older contracts that remained live despite being deprecated.

These findings align with broader industry trends. In a separate report, CertiK noted that while crypto hacks fell by 47% in the first half of 2026, the ecosystem is not necessarily safer. Operational failures—such as key compromise, phishing attacks targeting signers, and infrastructure vulnerabilities—have become the dominant vector for losses. This has prompted institutional investors to demand a more holistic view of risk.

Federico Bagiotti, group head of risk management at Abraxas Capital, contributed to the Hacken report by noting that "inadequate security relative to the capital at risk" was the signal that most often led his firm to reject an otherwise attractive position. This perspective is echoed by Rajeev Bamra of Moody's Ratings, who stated that operational resilience has become "the practical lens" through which institutions evaluate security, compliance, and governance.

Operational Security as a Key Metric

Operational security encompasses a wide range of factors that go beyond the code itself. The Hacken report indicates that institutional due diligence now regularly includes signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. Abraxas Capital, for example, explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies.

This shift is not limited to private investors. Regulators are also taking notice. The European Union's Digital Operational Resilience Act (DORA), which came into force in early 2025, requires financial institutions—including those dealing in crypto assets—to maintain robust operational resilience frameworks. A July 2026 report from Cointelegraph highlighted that BitGo's Chief Operating Officer, Jody Mettler, observed institutional clients asking more detailed questions about custody providers' access controls, incident response, and business continuity as European regulators examined compliance with DORA.

The Hacken dataset covered projects listed on the top 50 centralized exchanges by CoinGecko Trust Score, excluding wrapped assets, stablecoins, and tokenized real-world assets. The reliance on publicly observable and disclosed controls means that private arrangements—such as insurance policies or private key sharding—may not be fully captured. Nevertheless, the data provides a stark picture: the vast majority of crypto projects still lack continuous monitoring infrastructure.

Why Continuous Monitoring Matters

Static audits are point-in-time assessments. They reveal vulnerabilities present at the moment of review, but they cannot account for changes introduced later—such as software updates, new dependencies, or compromised admin keys. Continuous monitoring, by contrast, provides real-time visibility into a project's security posture. It can detect anomalous behavior, configuration drift, and unauthorized access attempts.

Bug bounty programs complement monitoring by incentivizing ethical hackers to discover and report vulnerabilities. When combined, monitoring and bug bounties offer a dynamic defense that evolves alongside threats. Yet the Hacken report found that only 4% of projects had all three elements: an audit, a bug bounty, and third-party monitoring. This low adoption rate is a concern for institutional investors who require assurance that their capital is protected.

The report also highlighted the role of signer controls. In many crypto projects, multisignature wallets are used to authorize transactions. However, if the signers themselves are compromised—through phishing, hardware wallet theft, or insider threats—the multisig offers little protection. Institutions are now asking about the security of signer devices, the frequency of key rotation, and the geographic distribution of signers to mitigate single points of failure.

Regulatory and Industry Implications

The shift toward operational security has implications for how crypto projects are evaluated by regulators and rating agencies. Moody's Ratings, under Bamra's leadership, has begun incorporating operational resilience metrics into its credit assessments of crypto-native firms. This could lead to lower credit ratings for projects that rely solely on audits without demonstrating ongoing monitoring capabilities.

Similarly, insurance providers are adjusting their underwriting criteria. Projects with active bug bounty programs and third-party monitoring may qualify for lower premiums, while those without could find coverage prohibitively expensive or unavailable. This creates a market incentive for projects to invest in continuous security measures.

On the investment side, venture capital firms and institutional funds are developing internal scoring systems that weight operational security factors heavily. A project with a recent audit but no monitoring may be scored lower than one with a slightly older audit but robust monitoring and a history of rapid incident response. This recalibration is already influencing deal flow, as startups seeking institutional backing must demonstrate not just code quality but also operational maturity.

Hacken's report serves as a wake-up call for the entire crypto ecosystem. The days when a single audit could unlock millions in institutional capital are fading. Trust must be earned continuously, not granted once. Projects that adapt by implementing comprehensive security programs—including monitoring, bug bounties, strong signer controls, and incident response plans—will be better positioned to attract and retain institutional investment.

The Q2 2026 data also offers lessons for the broader blockchain security industry. Security firms may need to expand their service offerings beyond audits to include ongoing monitoring, threat intelligence, and incident response retainer models. As institutional demand for operational security grows, the market for these services is likely to expand rapidly.

Finally, the report underscores the importance of community and transparency. Projects that publicly disclose their security controls, publish incident reports, and engage with security researchers tend to build more trust than those that operate opaquely. In an environment where trust signals are faltering, transparency may be the most valuable asset of all.


Source:Cointelegraph News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy