Home Crypto Crypto security audits lose trust as institutions demand live monitoring

Crypto security audits lose trust as institutions demand live monitoring

13
0



Institutional investors are widening crypto security checks beyond smart contract audits as operational failures become a larger source of losses. 

Summary

  • Institutions increasingly demand continuous monitoring as audits fail to capture key, signer and infrastructure risks.
  • Compromised keys, signers and infrastructure caused 88.3% of roughly $764 million stolen during Q2 2026.
  • Only 4% of tracked projects combined audits, active bug bounties and third-party monitoring controls together.

Hacken’s Q2 2026 Security & Compliance Report said traditional trust markers, including previous audits and operating history, did not reliably show which projects would avoid an exploit.

The report tracked 1,427 projects and found that only 9% showed evidence of third-party monitoring. Just 4% combined monitoring with an active bug bounty and an audit. Hacken said compromised keys, signers and infrastructure accounted for 88.3% of about $764 million stolen during the quarter, shifting attention toward controls that remain active after code reviews.

Hacken said institutions are asking whether security controls match the capital a protocol holds. Federico Bagiotti, group head of risk management at Abraxas Capital, said “inadequate security relative to the capital at risk” was the issue most likely to make the firm reject an otherwise attractive position.

Institutional reviews increasingly cover signer-set changes, collateral backing, outside service providers and incident-response plans. Abraxas also checks for timelocks, withdrawal-address whitelisting, multiparty controls and reliance on a single key or verifier. These measures focus on privileged access and emergency readiness rather than only whether contracts passed a review.

A separate H1 2026 report from CertiK also found that lower headline losses did not mean crypto had become safer. As crypto.news reported, crypto-related losses fell 46.8% year over year to $1.32 billion in the first half, but wallet compromises became the largest attack method in Q2. CertiK put Q2 losses from that category at $807.5 million under its own methodology.

Audited crypto projects still failed outside contract code

Hacken identified 14 projects exploited during Q2 that had previously completed audits. In many cases, the failure occurred outside the smart contract code covered by a conventional review. The affected areas included signer devices, bridge validators, backend systems, administrator keys and older contracts that remained active after teams stopped using them.

As crypto.news reported in June, Humanity Protocol lost about $36 million after malware on a developer device exposed seven private keys. Investigators said the attacker used valid credentials to authorize transactions, while the project’s smart contracts and Safe architecture were not themselves exploited.

A similar pattern appeared in two of the year’s largest reported attacks. Crypto.news previously reported that the Drift Protocol and KelpDAO incidents relied on social engineering, compromised devices and bridge infrastructure rather than direct smart contract flaws. Together, those attacks accounted for $577 million in losses.

Institutions demand continuous crypto security evidence

Rajeev Bamra, head of digital economy strategy at Moody’s Ratings, said operational resilience had become “the practical lens” through which institutions assess security, compliance and governance. Under that approach, an audit remains part of the review, but investors also seek evidence that teams monitor access and prepare for failures after deployment.

Institutional custody reviews are moving in the same direction. As crypto.news reported on July 11, European regulators launched a review of MiCA-authorized crypto custodians focused on private-key management, transaction controls, incident response and third-party technology risks. BitGo Chief Operating Officer Jody Mettler said institutional clients increasingly ask how custodians segregate assets, control access and maintain services during market stress.

Hacken’s dataset covered projects with market capitalizations above $1 million listed across the top 50 centralized exchanges by CoinGecko Trust Score. It excluded stablecoins, wrapped assets and tokenized real-world assets. The research relied on publicly visible or disclosed controls, so private security arrangements may not appear in the data.

Monitoring and incident readiness become allocation tests

The move toward continuous checks does not remove the role of smart contract audits. Hacken’s Q1 2026 report recorded six exploited protocols that had been audited, including one with 18 previous audits. The firm said security needs to cover code, operations and infrastructure throughout a project’s life rather than end when an audit report is published.

For investors, that wider review can include real-time monitoring, bug bounty programs, key-management design, signer separation and tested response plans. Projects that cannot show those controls may face more questions from allocators, insurers and counterparties before receiving capital or commercial access, according to Hacken’s Q2 findings.

Recent regulatory and security data follows the same pattern. ESMA is testing the operational resilience of licensed custodians, while CertiK found that targeted wallet compromises drove a large share of 2026 losses. For institutions assessing crypto exposure, the question is increasingly not only whether a project was audited, but whether its controls keep working afterward.





Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here