Crypto
Home›Crypto›Regulation›Crypto institutions shift due diligence toward continu…
Crypto institutions shift due diligence toward continuous monitoring
Hacken found that 88.3% of about $764 million stolen in Q2 2026 stemmed from compromised keys, signers, and infrastructure, prompting scrutiny of ongoing operational security.
Crypto institutions are increasingly moving beyond one-time trust signals like smart contract audits, placing more weight on continuous monitoring and operational resilience, according to Hacken. In its Q2 2026 Security and Compliance Report, Hacken said traditional indicators have not consistently helped predict which crypto projects would be exploited.
Hacken reported that only 9% of 1,427 tracked projects had third-party monitoring, and 4% combined monitoring with an active bug bounty and a security audit. The report highlighted that compromised keys, signers, and infrastructure accounted for 88.3% of roughly $764 million stolen during the quarter.
Hacken said projects that cannot provide ongoing evidence of operational security may be viewed as higher risk, face reduced investment, and have more difficult access to insurance or counterparties. The report also said institutional due diligence is incorporating checks such as signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits.
Hacken added that contributors including risk management and ratings executives described security relative to the capital at risk as a key rejection signal. Hacken said firms it cited now screen for controls such as timelocks, withdrawal-address whitelisting, multiparty controls, and reducing single-key or single-verifier dependencies.