Crypto institutions look beyond audits as trust signals falter: Hacken
Institutional investors are shifting from relying on past audits and track record to evaluating ongoing operational security. Hacken’s Q2 2026 report found only 9% of 1,427 tracked crypto projects had third-party monitoring, and just 4% combined monitoring, an active bug bounty, and a security audit. Most of the roughly $764 million stolen in the quarter came from compromised keys, signers, and infrastructure, not smart contract flaws. Due diligence is now expanding to include signer-set changes, custody controls, collateral backing, third-party dependencies, incident-response readiness, and audit scope/recency. Projects that cannot show continuous security evidence may face higher perceived risk, weaker investment demand, and harder access to insurance or counterparties. Even previously audited projects were exploited, showing that conventional audits often miss real attack surfaces such as admin keys, bridge validators, backend systems, and old live contracts.
