Traditional Audit Systems Lose Credibility as Crypto Firms Embrace New Security Measures: Hacken Report

Traditional Audit Systems Lose Credibility as Crypto Firms Embrace New Security Measures: Hacken Report

The cryptocurrency industry is moving away from conventional audits toward real-time surveillance, enhanced signer protocols and crisis preparedness following revelations that operational breakdowns caused the majority of digital asset losses.

Cryptocurrency institutions are moving away from relying solely on smart contract audits following the failure of conventional trust indicators like previous audits and established operational track records to accurately forecast which digital asset projects would suffer security breaches, based on findings from Hacken.

According to Hacken's Q2 2026 Security & Compliance Report, a mere 9% of the 1,427 projects analyzed maintained third-party monitoring systems, with just 4% implementing a comprehensive approach that included monitoring alongside an active bug bounty program and security audit. The analysis revealed that compromised keys, signers and infrastructure were responsible for 88.3% of approximately $764 million in stolen funds throughout the quarter.

According to Hacken, projects that cannot demonstrate continuous proof of operational security are likely to encounter elevated risk perceptions, diminished investment interest and more challenging pathways to obtaining insurance coverage or establishing counterparty relationships.

The report featured input from Federico Bagiotti, group head of risk management at Abraxas Capital, who indicated that "inadequate security relative to the capital at risk" represented the warning sign that most frequently caused the firm to turn down an otherwise appealing investment opportunity. Rajeev Bamra, Moody's Ratings' head of digital economy strategy, noted that operational resilience has emerged as "the practical lens" that institutions now use when assessing security, compliance and governance frameworks.

Security controls among reviewed projects
Security control implementation across examined projects. Source: Hacken

Operational security becomes an allocation test

According to the report, institutional due diligence processes are now incorporating factors such as signer-set modifications, collateral backing verification, third-party dependency analysis, incident-response preparedness and both the scope and timing of security audits. Abraxas Capital disclosed that it currently conducts explicit screening for timelocks, withdrawal-address whitelisting protocols, multiparty control mechanisms and dependencies on single-key or single-verifier systems.

This transformation has also manifested in regulatory and industry oversight practices. In a July 10 Cointelegraph report, BitGo Chief Operating Officer Jody Mettler revealed that institutional clients have started posing more granular questions regarding custody providers' access control systems, incident response capabilities and business continuity planning as European regulatory authorities evaluate operational resilience under the framework of the Digital Operational Resilience Act (DORA).

Hacken's findings indicated that 14 projects that were exploited during the second quarter had undergone previous security audits. Nevertheless, the bulk of financial losses originated from vulnerabilities lying beyond the parameters of traditional smart contract assessments. The compromised attack surfaces encompassed signer devices, bridge validators, backend infrastructure systems, admin keys and legacy contracts that continued to operate despite being deprecated.

The research dataset encompassed 1,427 projects possessing market capitalizations exceeding $1 million, selected from assets trading on the top 50 centralized exchanges according to CoinGecko Trust Score rankings. Hacken's methodology excluded wrapped assets, stablecoins and tokenized real-world assets from consideration. The organization's data collection depended on publicly visible and disclosed security controls, indicating that private security arrangements may not have been reflected in the analysis.

← Back to Blog