Regulators Raise the Bar as Web3 Security Lags Behind
-

Hacken researchers say regulators increasingly define what “good security” looks like—covering role-based access controls, institutional custody, logging, monitoring, and identity verification—but many Web3 firms still fall short.
Common failures include not revoking developer access, relying on single private keys, and lacking endpoint detection systems. Hacken warns that guidance alone hasn’t been enough.
Looking ahead to 2026, Hacken expects regulators to shift from soft recommendations to hard enforcement, especially around signing hardware, monitoring tools, and North Korea–specific threat defenses.
-
ppl still blaming smart contracts when most hacks are just compromised signers and bad ops. security is a people problem now