Hacken says 88.3% of Q2 crypto losses came from operational failures

Hacken says 88.3% of Q2 crypto losses came from operational failures

Its Q2 2026 report says institutional investors are shifting due diligence toward continuous monitoring, signer controls and incident readiness after roughly $764 million was stolen.

Fact Check
Three independent crypto news outlets — the originating Cointelegraph article, crypto.news, and bloomingbit — all attribute the identical figures to Hacken's Q2 2026 report: 88.3% of the ~$764 million stolen came from operational failures (compromised keys, signers, infrastructure) outside audit scope, and institutional investors are shifting due diligence toward continuous monitoring, signer controls and incident readiness. The consistency of the exact percentage and dollar figure across sources strongly corroborates the claim. The only limitation is that Hacken's primary report page returned a 404 during verification, so the assessment rests on secondary reporting rather than the original document.
    Reference123
Summary

Institutional crypto due diligence is moving beyond smart contract audits as investors focus more heavily on operational resilience after operational failures drove most losses in the second quarter, Hacken said in its Q2 2026 Security and Compliance Report. The firm said compromised keys, signers and infrastructure made up 88.3% of the roughly $764 million stolen in Q2, while only 9% of 1,427 tracked projects had third-party monitoring and just 4% combined monitoring with an active bug bounty and a security audit. Hacken said projects that cannot show ongoing evidence of operational security could face higher perceived risk, reduced investment and tougher access to insurance or counterparties. Federico Bagiotti, group head of risk management at Abraxas Capital, said the firm most often declines investments when security is inadequate for the capital being entrusted, while Rajeev Bamra, Moody’s Ratings’ head of digital economy strategy, said operational resilience had become the practical lens for assessing security, compliance and governance. The report said institutional due diligence is increasingly examining signer-set changes, collateral backing, third-party dependencies, incident-response readiness and the scope and recency of audits, while Abraxas now explicitly screens for timelocks, withdrawal-address whitelisting, multiparty controls and whether a project relies on a single key or single verifier. Hacken also said 14 projects exploited during the quarter had previously been audited, with many losses tied to areas outside conventional smart contract reviews, including signer devices, bridge validators, backend infrastructure, admin keys and deprecated contracts that remained live. The dataset covered 1,427 projects with market capitalizations above $1 million across assets listed on the top 50 centralized exchanges by CoinGecko Trust Score, excluding wrapped assets, stablecoins and tokenized real-world assets. BitGo Chief Operating Officer Jody Mettler said institutional clients have also begun asking more detailed questions about custody providers’ access controls, incident response and business continuity as European regulators examine operational resilience under DORA.

Terms & Concepts
  • smart contract audits: Security reviews of blockchain-based code intended to identify vulnerabilities in onchain programs.
  • bridge validators: Participants or systems that verify and authorize transfers of assets or messages between separate blockchains.
  • DORA: The Digital Operational Resilience Act, a European framework focused on operational risk management and resilience in financial services.