Institutional investors are intensifying their due diligence scope from smart contract audits to continuous monitoring, signer control, and incident response preparedness. This increased concern about security stems from alarming figures from Hacken’s Q2 2026 security and compliance report.
Institutional investors expanded their due diligence to a new dimension, going beyond smart contract audits, as Hacken’s Q2 2026 security and compliance report stated 750 million dollars in losses in Q2 of 2026.
According to Hacken’s Q2 2026 report, which tracked 1,427 projects, only 9% have third-party monitoring, and 4% have both monitoring, active vulnerability reward programs, and security audits. With such a low level of independent monitoring, the report reveals that 88.3% of the $764 million stolen in Q2 involved compromised keys, signers, and infrastructure.
Hacken’s report highlights that the 14 projects targeted in the second quarter had already undergone audits, yet most of the losses originated from vulnerabilities outside the traditional scope of smart contract reviews. The affected areas included signing devices, cross-chain bridge validators, backend infrastructure, administrator keys, and legacy contracts that were no longer actively maintained but remained operational. This highlights the growing need for broader security measures beyond conventional audits.
Smart contract audits remain an important security measure, but they only cover one part of a blockchain ecosystem. Audits primarily focus on identifying vulnerabilities within the code at a specific point in time, while many major exploits occur outside the smart contract layer, including compromised administrator keys, signing devices, backend infrastructure, and cross-chain bridge validators.
This is where third-party monitoring adds another layer of protection by continuously tracking the ecosystem for suspicious activity, unauthorized access attempts, and emerging risks after deployment. Unlike one-time audits, continuous monitoring provides real-time oversight and independent verification, helping projects maintain stronger security standards. For institutional investors, this broader security approach reduces operational risks and gives them more confidence that their capital is protected beyond the limitations of traditional audits.



