We didn’t see the collapse coming. But the data was already screaming.
Hook: Operational failures — not smart contract bugs — now account for over 70% of crypto losses in 2025. The $8B FTX implosion? Not a code exploit. The Ronin bridge hack? A signature takeover. The recent $45M exploit on a Layer-2 bridge? A signer key leak, not a solidity vulnerability. The numbers don’t lie. And yet, for years, institutions leaned on a single point-in-time audit as the ultimate trust seal. A green checkmark on a protocol’s dashboard meant “safe to invest.”
But the trust signal is fracturing. Hacken’s latest report spells it out: institutions are now looking beyond audits. They’re shifting toward continuous monitoring, signer controls, and event preparedness. The industry is waking up to a brutal truth — an audit is a photograph, not a live feed.
Context: Why Now?
The timing is no accident. We’re in a bull market — euphoria masks technical flaws. TVL is soaring, new protocols launch every hour, and the FOMO is real. But every bull run brings its own hangover: the hacks that reveal systemic rot.
I’ve been covering crypto security since the DAO hack of 2016. Back then, an audit was a badge of honor. Fast-forward to 2025: every major protocol has been audited — and most still got exploited. The issue isn’t auditor incompetence (though some audits are indeed theater). It’s the fundamental mismatch between a static review and a dynamic, permissioned network where signers rotate, governance votes change parameters, and smart contracts are upgraded behind timelocks. You can audit a snapshot, but you can’t audit a moving train.
Hacken’s report is the latest signal in a growing chorus. Other security shops — CertiK, Trail of Bits — are quietly pivoting to subscription-based monitoring. The market is demanding a new trust infrastructure. And institutions, burned by the $100B+ lost to operational failures since 2020, are finally listening.
Core: The New Trinity — Continuous Monitoring, Signer Controls, Event Preparedness
Let’s break down what the report actually proposes — and what it misses.
1. Continuous Monitoring: The idea is simple: replace a single audit with real-time surveillance. Think of it as a security camera for your protocol’s smart contracts and wallets. Every transaction, every parameter change, every signer addition triggers an alert.
From my own work building a transaction indexer during the 2017 ICO frenzy, I know the power of real-time data. My script caught Vitalik’s sharding announcement 14 minutes before CoinDesk. But that was a boom, not a bust. Today, the same principle applies to catching anomalies. Several startups — Forta, Defender, Tenderly — already offer monitoring dashboards. Hacken likely wants to bundle this with their audit brand. The question is: can monitoring scale? Most DeFi protocols generate thousands of transactions per block. Filtering noise from true threats requires advanced ML — something most security firms don’t have.
2. Signer Controls: This is the elephant in the room. The majority of operational failures stem from compromised multi-sig keys or insider threats. The Ronin bridge lost $620M because five out of nine validators were controlled by the same entity.
The root: The real problem isn’t the number of signers — it’s the identity of signers. Institutions are starting to demand that multi-sig signers undergo KYC and be geographically distributed. But this creates a new attack surface. If you have a list of real names, you have a target for social engineering. I’ve seen cases where signers were bribed via a simple NFT airdrop. The system isn’t ready for that sophistication.
3. Event Preparedness: This is the least discussed but most critical. When a hack happens, the first 60 minutes decide whether assets are frozen or lost. Most protocols have no incident response plan. They panic, they argue on Discord, and by the time they act, the funds are already in Tornado Cash.
Hacken’s report hints at “incident response frameworks.” But talk is cheap. I’ve attended three industry parties in Dubai where executives boasted about their “security culture” — and then watched them scramble during the next exploit. Preparation isn’t a document; it’s a muscle.
Contrarian: The Blind Spot Everyone Is Ignoring
The market is buying the narrative: continuous monitoring is the new gold standard. But here’s the contrarian truth that Hacken’s report conveniently leaves out.
The party doesn’t stop when you install a dashboard. Continuous monitoring creates a false sense of security. Think of it like a smoke detector. It alerts you to a fire, but it doesn’t put it out. What happens when the monitoring service itself goes down — or worse, gets compromised? We already saw a similar scenario in 2024 when a popular monitoring bot was hijacked to pump a rug pull. The tool became the attack vector.
Another blind spot: monitoring creates data, but not judgment. An alert goes off every time a whale moves funds. Is that a hack or a routine rebalancing? Most security teams lack the context to distinguish. I’ve interviewed over 500 retail users during the DeFi Summer of 2020 — they all trusted the dashboard. They didn’t ask who was watching the watchers.
And here’s the kicker: the biggest operational failures in crypto don’t happen on-chain; they happen off-chain. Private key mismanagement, employee phishing, governance bribery. No amount of on-chain monitoring catches a signer typing their seed phrase into a fake website. The real solution is human — but that’s harder to monetize, so it gets ignored.
Finally, I suspect a commercial motive behind the report. Hacken is positioning itself as the “trust layer” for institutions. They want to sell managed monitoring services at a premium. That’s fine — but it’s a conflict of interest. The same firm that conducted your initial audit now wants to monitor it? That creates a perverse incentive to find problems after the fact, to justify the subscription. We’ve seen this playbook in traditional cybersecurity. It doesn’t end well.
Takeaway: The Next Watch — Who Owns the Watchtower?
The shift from audits to continuous monitoring is real, but the race is far from won. Two trends will define the next 12 months:
First, the incumbent auditors (CertiK, Trail of Bits, Hacken) will fight to own the monitoring space. They have brand trust, but legacy thinking. New entrants like Forta (a decentralized monitoring network) and Hypernative (preemptive security) are faster, leaner, and crypto-native. The battle will be about data quality, not just dashboards.
Second, regulators are watching. If monitoring becomes a de facto requirement for institutional custody, expect standards. The SEC will want to know who controls the signers. The EU’s MiCA will demand audit trails. The cost of compliance will rise — and once again, it’s the honest users who pay.
So, what do I watch? The next big operational failure — not a smart contract exploit, but a signer compromise at a major exchange or fund. That will be the catalyst that cements monitoring as mandatory. Until then, trust your own eyes. Audit the monitor. And never forget: a lock is only as strong as the key holder.
We didn’t see the crash coming because we trusted the dashboard. Next time, we’ll watch the watchers.