Institutional Crypto Investors Expand Due Diligence Beyond Smart-Contract Audits
Summary
- Institutional investors say a smart-contract audit record alone is not enough to judge a project's credibility, and are expanding due diligence to cover broader operational security.
- Hacken said only 4% of tracked projects had third-party monitoring, bug bounties and security audits in place, while 88.3% of losses came from private key and infrastructure compromises.
- Executives at Abraxas Capital, Moody's and BitGo said operational resilience, access controls, incident response and business continuity have become the practical benchmarks institutions use to assess security and compliance.
Forecast Trend Report by Period



Institutional investors in digital assets are broadening due diligence beyond smart-contract audit histories, concluding that audits alone are not enough to assess a project's credibility.
Cointelegraph reported on July 20 that blockchain security firm Hacken, in its Q2 2026 Security and Compliance Report, found that only 9% of the 1,427 projects it tracked had third-party monitoring in place. Just 4% had all three safeguards: monitoring, bug bounties and security audits.
Hacken said 88.3% of the roughly $764 million in losses recorded in the second quarter came from compromises involving private keys, signers and infrastructure. The 14 projects hacked during the period had all previously been audited, but most losses stemmed from areas outside smart-contract audit coverage, including signer devices, bridge validators, backend infrastructure and admin keys.
Projects that cannot show ongoing evidence of operational security may face greater perceived risk, reduced investment and more limited access to insurance and counterparties, Hacken added.
Institutional due diligence is shifting as well. Federico Baggiotti, group head of risk management at Abraxas Capital, said the firm most often declines investments when it deems security inadequate for the capital being entrusted, even when a position appears attractive. Abraxas is now explicitly reviewing timelocks, withdrawal-address whitelists, multi-signature controls and whether a project relies on a single key or a single validator.
Rajeev Bamra, head of digital economy strategy at Moody's Ratings, said operational resilience has become the practical yardstick institutions use to assess security, compliance and governance. Jody Metler, chief operating officer at BitGo, said institutional clients have recently started asking more detailed questions about custodians' access controls, incident response and business continuity.
YM Lee
20min@bloomingbit.ioCrypto Chatterbox_ tlg@Bloomingbit_YMLEE