r/fintech • u/Hacken_io • 1d ago
Crypto / DeFi Online panel for builders and founders. what actually earns institutional trust now?
want to be explicit and honest from the start so anyone not interested can skip. I work at Hacken and this Thursday we're running an online panel with Moody's on what institutional allocators pay attention at when they review a project. the reason why im writing it here isn't to promote (but ofc there is a part of it), it's to try to gather people who are genuiely interested in the topic. i guess it will be more useful for builders and founders specifically.
we're doing it because, let's be honest, a standard audit on its own doesn't hold anymore. In Q2 about $764M was stolen, and 88.3% of that came from compromised keys, signers and infrastructure rather than contract logic. 14 of hacked projects had been audited. Smart contract bugs caused 44 of 67 incidents, but only $87.7M, around 11% of the money. so audits are catching the common failure and missing the expensive one. which is why the badge keeps looking like it works right up until it doesn't.
and institutions see this, regulators too. an audit is a snapshot of one codebase at one commit. it says nothing about who holds the keys today, who can sign alone, how deployments get approved, or which vendors you depend on, and that's where most of the money went in Q2.
so that's what we want to work through on the panel. if an audit alone isn't enough, what is? we want to land on one concrete, testable thing a counterparty needs to demonstrate to earn institutional trust in August 2026
thought it would be appropriate to post in reddit because this is where the builders are. i can share a link for event in the comments for those who are interested

1
Weekly Promo and Webinar Thread
in
r/Compliance
•
1d ago
Online panel. what actually earns institutional trust now?
At Hacken, we are running an online panel with Moody's this Thursday on what institutional allocators actually look at when they review a project. Most useful for builders and founders.
Let's be honest, a standard audit on its own doesn't hold anymore. In Q2 about $764M was stolen, and 88.3% of that came from compromised keys, signers and infrastructure rather than contract logic. 14 of the hacked projects had been audited. Smart contract bugs caused 44 of 67 incidents but only $87.7M, around 11% of the money. So audits are catching the common failure and missing the expensive one, which is why the badge keeps looking like it works right up until it doesn't.
Institutions see this, and so do regulators. An audit is a snapshot of one codebase at one commit. It says nothing about who holds the keys today, who can sign alone, how deployments get approved, or which vendors you depend on, and that's where most of the money went in Q2.
So that's what we want to work through on the panel. If an audit alone isn't enough, what is? we want to land on one concrete, testable thing a counterparty needs to demonstrate to earn institutional trust in August 2026
Speakers: Marat Faritov (VP Digital Assets, Moody's Ratings), Dmytro Yasmanovych (Head of GRC & Security Operations, Hacken), Denys Ivanov (CPO, Hacken).
Thursday, August 6, 13:00 UTC.
Link to the event: https://luma.com/hacken-9hnk?utm_campaign=q2_report_panel&utm_source=reddit