Institutional buyers are trying past good contract audits after conventional belief alerts comparable to prior audits and working historical past did not predict which crypto tasks could be exploited, in keeping with Hacken.
In its Q2 2026 Safety & Compliance Report, Hacken mentioned that solely 9% of 1,427 tracked tasks had third-party monitoring, whereas 4% mixed monitoring with an energetic bug bounty and a safety audit. The report highlighted that compromised keys, signers and infrastructure accounted for 88.3% of the roughly $764 million stolen through the quarter.
Hacken mentioned tasks unable to offer ongoing proof of operational safety might face greater perceived danger, decreased funding and harder entry to insurance coverage or counterparties.
Contributors to the report included Federico Bagiotti, group head of danger administration at Abraxas Capital, who mentioned “insufficient safety relative to the capital in danger” was the sign that almost all usually led the agency to reject an in any other case engaging place. Rajeev Bamra, Moody’s Scores’ head of digital financial system technique, mentioned that operational resilience had change into “the sensible lens” by means of which establishments evaluated safety, compliance and governance.
Safety controls amongst these reviewed. Supply: Hacken
Operational safety turns into an allocation take a look at
The report mentioned institutional due diligence is starting to incorporate signer-set adjustments, collateral backing, third-party dependencies, incident-response readiness and the scope and recency of audits. Abraxas mentioned it now explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls and single-key or single-verifier dependencies.
The shift has additionally appeared in regulatory and trade scrutiny. In a July 10 Cointelegraph report, BitGo Chief Working Officer Jody Mettler mentioned institutional purchasers had begun asking extra detailed questions on custody suppliers’ entry controls, incident response and enterprise continuity as European regulators examined operational resilience below the Digital Operational Resilience Act (DORA).
Associated: Crypto hacks fell 47% in H1 however ecosystem isn’t any safer: CertiK
Hacken mentioned 14 tasks exploited within the second quarter had beforehand been audited. Nevertheless, most losses stemmed from areas exterior the scope of typical good contract evaluations. The affected surfaces included signer gadgets, bridge validators, backend infrastructure, admin keys and older contracts that remained reside regardless of being deprecated.
The dataset coated 1,427 tasks with market caps above $1 million, drawn from property listed throughout the highest 50 centralized exchanges by CoinGecko Belief Rating. Hacken excluded wrapped property, stablecoins and tokenized real-world property. Its knowledge relied on publicly observable and disclosed controls, which signifies that personal preparations will not be captured.
Journal: Ethereum’s EEZ might pull different blockchains into its orbit

