
Hacken: Q2 crypto theft skewed to key and infrastructure failures, not contract bugs
The firm’s Q2 2026 report pegs 88.3% of $764M stolen to keys, signers and infrastructure, pressuring institutions to demand continuous controls.
Hacken’s Q2 2026 Security & Compliance Report attributed 88.3% of roughly $764 million stolen during the quarter to compromised keys, signers and infrastructure. The breakdown is pushing institutional due diligence away from one-off smart-contract audits and toward continuous operational-security evidence like monitoring, signer controls, and incident readiness.
Key Takeaways
- Compromised keys, signers and infrastructure drove 88.3% of roughly $764 million stolen in Q2 2026, per Hacken’s Q2 2026 Security & Compliance Report.
- Third-party monitoring remains thin across the sample: 9% of 1,427 tracked projects had it, and 4% paired monitoring with an active bug bounty and a security audit.
- Prior audits did not screen out losses in Q2, with 14 exploited projects previously audited and many incidents tied to signer devices, bridge validators, backend systems, admin keys, or older contracts still live.
- Hacken’s dataset covered 1,427 projects above $1 million market cap drawn from assets listed on the top 50 centralized exchanges by CoinGecko Trust Score, excluding wrapped assets, stablecoins, and tokenized real-world assets.
Q2’s $764M Theft Tally Points Away From Smart-Contract Bugs
Hacken’s Q2 2026 Security & Compliance Report put total theft for the quarter at roughly $764 million and assigned the bulk of that damage to operational failure modes. Compromised keys, signers and infrastructure accounted for 88.3% of the losses, a split that shifts the center of gravity away from pure smart-contract vulnerability narratives.
For allocators and traders, the implication is mechanical. If most losses are being attributed to key custody, signer compromise, and infrastructure weaknesses, then the diligence bottleneck is less about whether code once passed review and more about whether the system can resist or contain privileged-access failures.
The report also flagged a limitation that matters when interpreting the numbers: Hacken’s assessment relied on publicly observable and disclosed controls, which means private security arrangements may not be captured.
From “Audited” to “Operationally Resilient”: How Institutions Are Rewriting Due Diligence
Institutional screening is increasingly framed in operational resilience terms, not just “audited” labels. Rajeev Bamra, head of digital economy strategy at Moody’s Ratings, described operational resilience as “the practical lens” institutions use to evaluate security, compliance and governance.
Federico Bagiotti, group head of risk management at Abraxas Capital, put the rejection criterion in capital terms, saying “inadequate security relative to the capital at risk” is the signal that most often kills an otherwise attractive position.
Hacken’s report described diligence expanding into signer-set changes, collateral backing, third-party dependencies, incident-response readiness, and the scope and recency of audits. Abraxas said it explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls, and single-key or single-verifier dependencies. In practice, those controls are designed to slow down or block catastrophic admin actions, and to make privileged operations harder to execute with a single compromised device or operator.
The Adoption Gap: Monitoring and Full Security Programs Remain Rare
The report’s adoption stats show why institutions are asking for ongoing evidence that many projects still do not publicly provide. Across 1,427 tracked projects, only 9% had third-party monitoring, defined as ongoing external surveillance of on-chain and operational security signals. Only 4% combined monitoring with an active bug bounty and a security audit.
That gap does not prove causality. The dataset does not establish whether monitoring and bounties reduce exploit risk, or whether they simply correlate with more mature teams. What it does establish is a measurable shortfall in “continuous security” signaling, which can translate into higher perceived risk, tighter position limits, and more friction with insurers and counterparties.
Signals Traders Can Track Next: Monitoring, Signer Controls, and Resilience Under DORA Scrutiny
The next clean signal is disclosure. If projects begin publishing verifiable third-party monitoring coverage, the 9% figure should rise in subsequent quarterly datasets, and the market will have a clearer way to separate teams that operationalize security from teams that market it.
Incident flow is the other tell. New disclosures involving signer and key management, bridge validator sets, or admin-key controls would reinforce Hacken’s claim that these are the dominant loss drivers.
Regulatory pressure is a third vector. Operational resilience is being examined in Europe under the Digital Operational Resilience Act (DORA), and custody providers are already fielding more detailed questions on access controls, incident response, and business continuity. Follow-on Hacken quarterly breakdowns will matter most if the share attributed to keys, signers, and infrastructure remains dominant versus smart-contract vulnerabilities.
Why “Key Risk” Is Becoming the New Liquidity Risk for DeFi Allocations
I treat Hacken’s 88.3% figure as a market-structure datapoint, not a headline. If theft is mostly happening through keys, signers, and infrastructure, then “audited” becomes a weak filter and operational controls become the real gating factor for size, leverage, and counterparty comfort.
The threshold that matters is whether projects can produce continuous, verifiable evidence of monitoring and privileged-access constraints, because that is what turns security from a narrative badge into an enforceable risk parameter that institutions can underwrite.