Institutions Shift Due Diligence After Crypto Operational Hacks
Hacken found compromised keys, signers and infrastructure caused 88.3% of about $764 million stolen in Q2 2026, prompting institutions to widen due diligence beyond audits.
Hacken’s Q2 2026 Security & Compliance Report found that compromised keys, signers and infrastructure accounted for 88.3% of roughly $764 million stolen in the second quarter. The firm tracked 1,427 projects with market capitalizations above $1 million listed on exchanges ranked among the top 50 by CoinGecko Trust Score.
Only 9% of those projects had third-party monitoring, and 4% combined monitoring with an active bug bounty and a security audit. Fourteen projects exploited during the quarter had previously been audited, while most losses originated in areas outside traditional smart-contract reviews.
Hacken identified the most affected attack surfaces as signer devices, bridge validators, backend infrastructure, admin keys and older contracts that remained live despite being deprecated. The dataset excluded wrapped assets, stablecoins and tokenized real-world assets, and relied on publicly observable and disclosed controls.
Institutional investors are expanding due diligence to include ongoing operational factors. Firms are reviewing signer-set changes, collateral backing, third-party dependencies, incident-response readiness and the scope and recency of audits when evaluating positions.
Abraxas Capital now screens for timelocks, withdrawal-address whitelisting, multiparty controls and single-key or single-verifier dependencies. Federico Bagiotti, group head of risk management at Abraxas Capital, stated that “inadequate security relative to the capital at risk” was the signal that most often led the firm to reject an otherwise attractive position.
Rajeev Bamra, head of digital economy strategy at Moody’s Ratings, described operational resilience as “the practical lens” institutions use when judging security, compliance and governance.
Custody providers report that institutional clients are asking more detailed questions about access controls, incident response and business continuity as European regulators apply the Digital Operational Resilience Act to examine operational resilience.
Hacken warned projects unable to provide ongoing evidence of operational security may face higher perceived risk, reduced investment and greater difficulty obtaining insurance or working with counterparties. The report noted that private or undisclosed controls may not appear in the dataset, so some projects may have operational measures that were not captured.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.







