Institutional investors have stopped accepting a smart contract audit as sufficient proof that a crypto project is secure, after audits and lengthy operating records repeatedly failed to flag which platforms would be exploited, according to Hacken.

The conclusion anchors the firm’s Q2 2026 Security & Compliance Report, cited by Cointelegraph, which found that compromised keys, signers and infrastructure accounted for 88.3% of the roughly $764 million stolen during the quarter—losses that originated in areas a code review is not designed to examine.

Audited Crypto Projects Still Lost Funds

Fourteen projects breached in the second quarter had already passed an audit, yet the bulk of the stolen funds moved through surfaces that fall outside a smart contract review—signer devices, bridge validators, backend infrastructure, admin keys and deprecated contracts left running long after teams intended to retire them. Monitoring of those surfaces remains rare, with only 9% of the 1,427 projects Hacken tracked employing third-party monitoring and just 4% combining it with an active bug bounty and an audit.

That exposure mirrors the pattern behind the year’s largest breaches, when more than $600 million drained from crypto projects by the end of April, led by the $292 million Kelp DAO exploit—an attack tied to North Korea’s Lazarus Group that turned on a bridge secured by a single verifier and not a coding flaw. Losses slowed into midyear, with $75.9 million stolen in June through the Humanity Protocol breach, whose attacker laundered funds across Bitcoin, Solana, Hyperliquid and BNB Chain. The trend held even where recovery followed, as Foom Cash retrieved $1.84 million of a $2.26 million loss traced to an operational lapse instead of a cryptographic break.

Institutions Now Vet Signers

Due diligence now reaches well beyond the audit certificate, tracking who can approve crypto transactions, whether real collateral backs a position and how well a team can respond once an attack lands. Abraxas Capital now screens for timelocks, whitelisted withdrawal addresses and any single point at which one key governs everything, with group head of risk management Federico Bagiotti saying “inadequate security relative to the capital at risk” most often led the firm to abandon an otherwise attractive position.

Rajeev Bamra, head of digital economy strategy at Moody’s Ratings, described operational resilience as “the practical lens” institutions apply when assessing a project, a shift steering teams toward multiparty computation, a custody model that divides a private key so no single party can move funds alone. Hacken cautioned that projects unable to demonstrate such controls on an ongoing basis risk higher scrutiny, thinner investment and narrower access to insurers and counterparties.