Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Hacken at 9: Digital Assets Are Emerging as a Strategic Priority for Financial Institutions

6 min read

On August 2, Hacken turns 9. This happened amid GENIUS in force, CLARITY discussions in the Senate, and MiCA being in full force across all EU members for the first month. Digital assets have become a new reality for financial institutions: Stablecoins are being tested as payment methods, ETFs and ETNs are trading on major exchanges, and governments are running CBDC pilots. The largest digital asset ecosystems have become components of the wider financial system.

Hacken has spent those nine years securing more than 2,000 blockchain entities across every market cycle.

Nine years ago, those teams were concerned with whether the code was safe. Nine years later, the list of answers needed to prove trust expanded drastically. Today, we want to share where the market is heading next, what we are doing to be ready, and how our clients have grown with us.

Digital Assets Are Scaling to Meet Institutional Requirements

Potentially attractive digital asset deals stall because counterparties cannot present verifiable, continuous evidence of safety and soundness.

It is what different contributors concluded from their vantage points in Hacken's Q2 report.

It’s not enough for an issuer to solve a problem with blockchain technology and rely on community trust alone. In early 2017, when Hacken emerged, the digital assets market capitalisation was $16B; today it is $2.2T, 137 times what it was. This scaling presents new challenges for assets entering institutional markets:

  • Digital assets must present clear value where blockchain outperforms legacy finance
  • Protocols must integrate well with legacy finance, offering as little friction as possible
  • On-chain finance must operate 24/7/365, while keeping custody risk to a minimum 
  • Digital asset issuers and service providers must meet governance and compliance requirements

Nevertheless, digital assets have begun to meet these requirements. And this is evident in how adversaries now target issuers, with 88% of Q2 2026 losses attributable to off-chain attacks. In other words, malicious actors attack digital asset issuers just like public companies, targeting operations through dependencies, social engineering, and the compromise of secrets.

Security standards are only half of the entry requirement. Regulators write the other half, and that half did not exist when Hacken started.

In 2017, the first regulatory intent headlines were only beginning to appear. Public markets were sceptical that money could be programmed and largely did not participate. Hacken emerged in that period as a code security partner, because secure code was the first marker of trust in the Web3 market.

Nine years later, the regional CASP/VASP landscape is largely built, but almost nowhere is complete. Of the 75 economies tracked by the Atlantic Council, crypto is legal in 45, partially banned in 20, and generally banned in 10. Only 28 of those 75 regulate across all four areas institutions care about: taxation, AML/CFT, consumer protection, and licensing. 

Regulators granted market access on the assumption that these risks are controlled. A major loss inside a regulated venue would be read as a failure of the asset class rather than of a single issuer, and access could be limited on that basis.

How Hacken Offerings Change with Crypto’s Challenges

Over past years, Hacken has consistently introduced solutions to address client challenges as they emerged. Hacken's year-by-year solutions list tracks how trust requirements evolved across digital asset markets. 

This timeline records how the blockchain industry's changes shaped Hacken's offerings. One example of spotting a contrast is seeing DDoS resistance testing listed as a blockchain security in 2019, when MiCA today asks an entity to demonstrate compliance across dozens of articles at once.

Each year, Hacken received new requests that were later added as standalone solutions. This development marks a shift in the requirements for being a trusted digital asset issuer

"What defines Hacken's DNA is not any single reinvention, but the three habits that make reinvention possible: adaptability to move with the market, curiosity to see what's next, and critical thinking to separate signal from noise. In the AI era, those are the only durable advantages a security, compliance and risk partner can offer."

— Dyma Budorin, Founder & CEO, Hacken

In 2017, allocators asked, “Are you secure on-chain?” Today, an issuer proves that it holds a licence, operates to a recognised security standard, and increasingly carries insurance. Without those, institutional capital is closed in most jurisdictions.

And the standard of what it takes to be trusted is not settled yet. The digital asset industry is still young, with solutions yet to be secured, regulations yet to be met, and a great deal left to change about how finance behaves on-chain. 

Where the Market Heads Next

Regulation already functions as an entry barrier. Entities that cannot demonstrate trust by meeting regulatory standards are being excluded from jurisdictions and, with them, from economies.

The institutions' setting direction differs in magnitude rather than in outcome. JP Morgan puts tokenised securities at roughly $30B today and is projecting an addressable value of $4T to $16T by 2030. Citi projects $5.5T by 2030 and has raised its stablecoin issuance forecast to $1.9T in the base case. Deloitte expects most commercial real estate fund managers to use blockchain-enabled digital assets in at least one part of the fund-flow process by 2030. Moody's describes digital finance as becoming a foundational infrastructure layer in 2026 and, in March, became the first credit rating agency to publish on-chain insights.

The same institutions name the constraint. In the EY-Parthenon and Coinbase survey of more than 350 institutional investors conducted in January 2026, an uncertain regulatory environment was the leading concern at 66% and the largest barrier to investing in tokenised assets at 67%. Regulated products are preferred by 81%. The capital is committed in principle and waiting on evidence.

Adversaries have set a second barrier. What was once a question of on-chain security is now a challenge of protecting the people layer, mapping dependencies, and defending financial models against manipulated data. Every layer must be equally protected, controlled, and documented.

"We can see what digital finance still lacks: an infrastructure of continuous trust. Cybersecurity can no longer end with a single assessment. Risk must be understood in real time, infrastructure protected continuously, and compliance maintained as regulation evolves. Hacken’s role is to bring these capabilities together and make institutional adoption safer." 

— Kostiantyn Harniuk, COO, Hacken

As digital asset finance becomes institutional, trust is increasingly measured through evidence of cybersecurity, risk intelligence, and compliance controls. Hacken focuses on helping organisations build that trust with solutions designed for on-chain environments. In parallel, we continue to develop our offerings so that as adversaries evolve, our clients remain ahead of them.

Nine Forces Shaping the Next Arc

The next phase of digital assets is already visible. Nine developments will define it, and they divide unevenly: six where the industry gains ground, three where new exposure appears.

Each of these will affect every institution in this space, which is why Hacken is already working on all nine, ahead of the regulation that will eventually require them.

Hacken Prepares for Public Capital Markets

For nine years, we have been the ones asking questions. A firm that requires verifiable evidence of how its clients are run cannot exempt itself, and the market has stopped permitting the exemption. HAI Group is preparing to list on a US exchange. The same requirements now apply to us: internal and external audits, security certifications, and governance and reporting that hold up under outside examination.

Hacken was born on blockchain; for many in the Web3 industry, operating for nine straight years would be an achievement in itself. Yet, we are moving toward the standards of liability and trust that the digital asset markets require today and will require in the future. We now intend to present the same transparency, security, and liability standards we asked of our clients.

Next: Staying Ahead in a Frontier Financial System

Digital assets are becoming regulated financial infrastructure, and their security can no longer be episodic. Like trust itself, safety and compliance have to be maintained continuously, proven repeatedly, and verifiable at any moment.

Nine years ago, Hacken was helping clients prove that their code was reviewed and secure. Today, as the architecture of trust changes, Hacken helps clients to provide evidence that they can be trusted on regulated markets. 

Subscribe to our newsletter

Be the first to receive our latest company updates, Web3 security insights, and exclusive content curated for the blockchain enthusiasts.

Speaker Img