Institutions Ditch Traditional Trust Signals for Operational Resilience
Institutional investors are reevaluating their approach to crypto security after traditional trust signals failed to predict which projects would be exploited, according to a recent report from Hacken.
The Q2 2026 Security & Compliance Report found that only 9% of 1,427 tracked projects had third-party monitoring, and just 4% combined monitoring with an active bug bounty and security audit.
Compromised keys, signers, and infrastructure accounted for a staggering 88.3% of the roughly $764 million stolen during the quarter, highlighting the need for more robust security measures.
Federico Bagiotti, group head of risk management at Abraxas Capital, said that inadequate security relative to the capital at risk was the signal that most often led his firm to reject an otherwise attractive position.
As a result, institutions are now looking beyond traditional audits and examining operational resilience, including signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits.




