Approximately $764 million stolen from crypto projects in Q2, with 88.3% involving keys, signers, and infrastructure
Odaily reports that in its Q2 2026 Security and Compliance Report, Hacken stated that institutional investors are expanding their due diligence scope from smart contract audits to continuous monitoring, signer control, and incident response preparedness. Among the 1,427 projects it tracked, only 9% had third-party monitoring, and 4% had monitoring, active bug bounties, and security audits simultaneously. The report shows that of the approximately $764 million stolen in Q2, 88.3% involved compromised keys, signers, and infrastructure.
Hacken noted that 14 projects attacked in Q2 had previously completed audits, but most of the losses originated from areas outside the scope of traditional smart contract reviews. The report states that the affected components included signing devices, cross-chain bridge validators, backend infrastructure, admin keys, and deprecated but still active old contracts. The sample covered 1,427 projects with a market cap exceeding $1 million, listed among the top 50 centralized exchanges on the CoinGecko Trust Score, excluding wrapped assets, stablecoins, and tokenized real-world assets.
