Crypto security audits lose trust as institutions demand live monitoring
Institutional investors are widening crypto security checks beyond smart contract audits as operational failures become a larger source of losses.
Summary
- Institutions increasingly demand continuous monitoring as audits fail to capture key, signer and infrastructure risks.
- Compromised keys, signers and infrastructure caused 88.3% of roughly $764 million stolen during Q2 2026.
- Only 4% of tracked projects combined audits, active bug bounties and third-party monitoring controls together.
Hacken's Q2 2026 Security & Compliance Report said traditional trust markers, including previous audits and operating history, did not reliably show which projects would avoid an exploit.
The report tracked 1,427 projects and found that only 9% showed evidence of third-party monitoring. Just 4% combined monitoring with an active bug bounty and an audit. Hacken said compromised keys, signers and infrastructure accounted for 88.3% of about $764 million stolen during the quarter, shifting attention toward controls that remain active after code reviews.
Hacken said institutions are asking whether security controls match the capital a protocol holds. Federico Bagiotti, group head of risk management at Abraxas Capital, said "inadequate security relative to the capital at risk" was the issue most likely to make the firm reject an otherwise attractive position.
Institutional reviews increasingly cover signer-set changes, collateral backing, outside service providers and incident-response plans. Abraxas also checks for timelocks, withdrawal-address whitelisting, multiparty controls and reliance on a single key or verifier. These measures focus on privileged access and emergency readiness rather than only whether contracts passed a review.
A separate H1 2026 report from CertiK also found that lower headline losses did not mean crypto had become safer. As crypto.news reported, crypto-related losses fell 46.8% year over year to $1.32 billion in the first half, but wallet compromises became the largest attack method in Q2. CertiK put Q2 losses from that category at $807.5 million under its own methodology.
Audited crypto projects still failed outside contract code
Hacken identified 14 projects exploited during Q2 that had previously completed audits. In many cases, the failure occurred outside the smart contract code covered by a conventional review. The affected areas included signer devices, bridge validators, backend systems, administrator keys and older contracts that remained active after teams stopped using them.
As crypto.news reported in June, Humanity Protocol lost about $36 million after malware on a developer device exposed seven private keys. Investigators said the attacker used valid credentials to authorize transactions, while the project's smart contracts and Safe architecture were not themselves exploited.
A similar pattern appeared in two of the year's largest reported attacks. Crypto.news previously reported that the Drift Protocol and KelpDAO incidents relied on social engineering, compromised devices and bridge infrastructure rather than direct smart contract flaws. Together, those attacks accounted for $577 million in losses.
Institutions demand continuous crypto security evidence
Rajeev Bamra, head of digital economy strategy at Moody's Ratings, said operational resilience had become "the practical lens" through which institutions assess security, compliance and governance. Under that approach, an audit remains part of the review, but investors also seek evidence that teams monitor access and prepare for failures after deployment.
Institutional custody reviews are moving in the same direction. As crypto.news reported on July 11, European regulators launched a review of MiCA-authorized crypto custodians focused on private-key management, transaction controls, incident response and third-party technology risks. BitGo Chief Operating Officer Jody Mettler said institutional clients increasingly ask how custodians segregate assets, control access and maintain services during market stress.
Hacken's dataset covered projects with market capitalizations above $1 million listed across the top 50 centralized exchanges by CoinGecko Trust Score. It excluded stablecoins, wrapped assets and tokenized real-world assets. The research relied on publicly visible or disclosed controls, so private security arrangements may not appear in the data.
Monitoring and incident readiness become allocation tests
The move toward continuous checks does not remove the role of smart contract audits. Hacken's Q1 2026 report recorded six exploited protocols that had been audited, including one with 18 previous audits. The firm said security needs to cover code, operations and infrastructure throughout a project's life rather than end when an audit report is published.
For investors, that wider review can include real-time monitoring, bug bounty programs, key-management design, signer separation and tested response plans. Projects that cannot show those controls may face more questions from allocators, insurers and counterparties before receiving capital or commercial access, according to Hacken's Q2 findings.
Recent regulatory and security data follows the same pattern. ESMA is testing the operational resilience of licensed custodians, while CertiK found that targeted wallet compromises drove a large share of 2026 losses. For institutions assessing crypto exposure, the question is increasingly not only whether a project was audited, but whether its controls keep working afterward.
Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.
You may also like

Recreating the 'DeepSeek Moment'? Wall Street Says Kimi K3 Actually Strengthens Demand for Computing Power

What is isolated margin and cross margin? The trading minute

Ripple veteran regrets selling XRP at $0.10 and Ethereum near $1

Bitcoin Approaches $70,000! July 21 Assessment

WAIC Observation: Crowded Consensus, Huge Bubble

What is 'Currency'? Exploring the History of Digital Money and the Duality of Currency and Assets (Episode 10 of 'So That's How Blockchain Works')

Bitcoin at $72,000: The $2.5 Billion Bet Timed for the Fed Meeting

Bitcoin ETF: Two Consecutive Weeks in the Green

Polymarket refers nearly 100 wallets amid $200M insider-trade concerns

Has Trustlessness Erased Trust? - A Reconfiguration of Verification | HashHub Research

HashKey taps Kbank, BPMG in South Korea stablecoin payments push

Did Vlad Follow Pons to Claim the Robinhood Chain Launchpad Throne?

10-Day Ceasefire Proposal Emerges, but Energy, Shipping, and Capital Cost Risk Chains Remain Unresolved

US SEC Sues Massachusetts Cryptocurrency Mining Company Mining Automatic: Features of a Ponzi Scheme

Airbnb CEO's X Account Compromised, AI-Generated Cryptocurrency Posts Spread

JPMorgan Remains Bullish on Korean Stocks: Leverage Pressure Has Been Significantly Released, Maintains Overweight Rating

ZachXBT Recommends Dedicated iPhone Amid Controversy Over Cryptocurrency Wallet Security

Distribution Comes First Before Relief Rally: Alea Research Diagnoses Market Battleground for the Second Half

IOSG: A Comprehensive Analysis of Robinhood's Self-Built L2, From Meme Cold Start to RWA Implementation

Important News from Last Night and This Morning (July 20 - July 21)

Cardano Activates Van Rossum Hard Fork and Expands Network Governance

Protecting Social Infrastructure through Games: The Frontline of Power and Local Government DX|WebX2026

Goldman Sachs: U.S. Inflation is Shifting from Localized to Widespread, but Far from Repeating the 2022 Crisis

Bitcoin in a Range: Is it a Signal for Accumulation? Crypto.com Highlights ETF Inflows and Regulatory Developments

Zcash Price Prediction: Can ZEC Hit $600 Before the July 28 Ironwood Upgrade?

Bank of Korea to Launch Phase 2 of CBDC Pilot in September, Targeting 500,000 Users

Coinbase backs tougher CLARITY Act as Trump ethics fight deepens

Pokémon Cards Become a Craze on Crypto Betting Platforms

Dash Financial Autonomy: The Future of Monetary Freedom








