Guavy AI Editorial TeamSentiment: -3Clout: 80

Institutional Investors Rethink Crypto Security Amid Exploits

Institutional investors are rethinking their approach to evaluating crypto projects' security after traditional trust signals failed to predict which ones would be exploited, according to a report by Hacken.

The Q2 2026 Security & Compliance Report found that only 9% of the 1,427 tracked projects had third-party monitoring, and just 4% combined this with an active bug bounty and security audit. Compromised keys, signers, and infrastructure were responsible for 88.3% of the approximately $764 million stolen during the quarter.

Hacken warns that projects unable to demonstrate ongoing evidence of operational security may face higher perceived risk, reduced investment, and difficulty accessing insurance or counterparties. Abraxas Capital's group head of risk management, Federico Bagiotti, said inadequate security relative to capital at risk was the signal most likely to lead his firm to reject an attractive position.

Rajeev Bamra, Moody's Ratings' head of digital economy strategy, noted that operational resilience has become 'the practical lens' through which institutions evaluate security, compliance, and governance. The report highlights a shift in institutional due diligence to include signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits.