Svmuu News: In its Q2 2026 Security and Compliance Report, Hacken stated that institutional investors are expanding the scope of their due diligence from smart contract audits to include continuous monitoring, signer controls, and incident response preparedness. Of the 1,427 projects it tracks, only 9% have third-party monitoring, and 4% have all three: monitoring, active bug bounties, and security audits. The report shows that of the approximately $764 million in funds stolen during the second quarter, 88.3% involved compromised keys, signers, and infrastructure.
Hacken noted that 14 projects attacked in the second quarter had previously undergone audits, but most of the losses stemmed from areas outside the scope of traditional smart contract reviews. The report stated that affected areas included signing devices, cross-chain bridge validators, backend infrastructure, administrator keys, and legacy contracts that had been deprecated but were still in operation. The sample covered 1,427 projects listed on centralized exchanges ranked in the top 50 by CoinGecko’s Trust Score, with a market capitalization exceeding $1 million, excluding wrapped assets, stablecoins, and tokenized real-world assets.