Immunefi recorded 207 hack incidents in H1 2026, the highest count on record, while total losses fell below $1 billion which is less than half the first half of 2025.
Attacks became more frequent and less expensive per event, and the firm placed the most severe damage in infrastructure failures, private key compromises, cross-chain configuration errors and weaknesses in privileged access rather than in protocol code.
An industry preparing to move trillions of dollars of regulated assets onto these rails is being gated by the layer it audits least.
Where the Losses Actually Happen
A decade of incident data has produced a finding that security budgets still do not reflect. Consensus mechanisms and settlement layers have held up under load.
What fails, repeatedly, is the ring of systems around them: wallets, signing infrastructure, administrative accounts, and the integrations connecting them to everything else.
Those systems are governed by process rather than by cryptography. A cryptographic guarantee holds whether or not anyone is watching.
A process guarantee holds only as long as someone owns it, and is answerable when it lapses.
If the failure surface is operational, the control that matters is a documented custody and access regime rather than a better chain.
That is a governance question before it is an engineering one, and governance questions get answered by whoever can be held to a standard.
The record also shows the sector fixes what it measures. Bridge exploits, once responsible for the majority of decentralized finance losses, have largely receded, and flash-loan attacks now account for a fraction of a percent of losses.
Both were counted, named and designed against. The categories replacing them have not been.
“As tokenization moves into the mainstream, the security conversation has to extend beyond the blockchain itself,” says Jimmy Su, Chief Security Officer at Binance.
“The most significant risks increasingly sit across the surrounding infrastructure—from smart contracts and custody to identity, key management, APIs and privileged access. Addressing those risks requires institutional-grade custody, continuous threat detection, rigorous access controls and security embedded throughout the product lifecycle. At Binance, our focus is on helping define the standards, controls and operational resilience the industry will need to support tokenized assets at scale. Security should not be treated simply as a compliance obligation; it is the foundation for earning institutional and user trust, and ultimately for enabling mainstream adoption.”
Custody Became a Controls Problem
Control that once sat inside core banking systems now has to be applied at the wallet layer, which turns custody into a control plane rather than a storage location.
Fireblocks notes that the SEC’s September 2025 no-action letter shifted what proper custody is understood to require for digital assets.
The components are documented well enough to be benchmarked. Elliptic’s custody taxonomy covers cold storage, multi-signature arrangements, multi-party computation and hardware security modules, and it is explicit that technical controls are the smaller half of the work: physical security, tested disaster recovery, key backup under access controls and personnel screening carry comparable weight.
Segregation is the load-bearing requirement. Separating client assets from operational funds means separate wallet infrastructure, documented audit trails, regular reconciliation, multi-party authorization for any movement between segregated wallets, and independent audits of the separation itself.
Commingling has sat at the centre of enough failures that institutional counterparties treat it as a first-order question.
Proving that separation without exposing wallet addresses is what pushed verification into a layer of its own.
Chainlink’s Proof of Reserve verifies backing through custodial APIs and audited data sources instead of public addresses, and runs in production for a regulated exchange-traded product issuer through Crypto Finance.
So custody has stopped being a question about where assets sit and become a question about what an operator can evidence. Grand View Research estimates the crypto custody market at roughly $683 billion in 2024. The firm projects it to exceed $4 trillion by 2033.

The Regulated On-Ramp Is Being Built Around Custody
Citi Institute put the tokenized asset market at roughly $17 billion in April 2026 under its own classification framework, and projects $5.5 trillion by 2030 in a base case and $8.2 trillion in a bull case.
The same research rates asset tokenization at 1.5 out of 10 on an adoption curve, which is the more informative figure, since these are forecasts built on a very early base.

The institutional facts underneath them are firmer. The DTCC received regulatory clearance in late 2025 to offer tokenization services for assets it custodies, with a pilot for limited production trades beginning in July 2026 and full commercial launch scheduled for October.
The NYSE secured SEC approval for its tokenized securities rule change in April 2026, and Nasdaq received approval in March 2026 for tokenized trading of Russell 1000 stocks and major index ETFs on the same order books as conventional shares.
What those institutions are extending onto blockchain rails is custody, clearing and settlement. The trading mechanics already work.
That makes the gating question for each programme whether control standards on the new rails match the ones on the old, and it explains why regulators have spent the past year licensing structure rather than technology.
The ADGM Financial Services Regulatory Authority took that approach in December 2025, granting full authorization across three separately licensed Binance entities: Nest Exchange as a recognised investment exchange, Nest Clearing and Custody as a recognised clearing house permitted to provide custody and operate a central securities depository, and Nest Trading as a broker-dealer.
Splitting those functions into distinct regulated entities reproduces the shape the traditional system already has, which is what makes an operator legible to an institutional counterparty.
Who Sets the Floor
Whether tokenized assets can be held securely has largely been settled by the operators already doing it at scale.
What remains open is narrower and harder. This is the following: which control standards become the baseline, who verifies them as well as how much of the market can meet them before the regulated on-ramps open.
Those answers may shape the pace of the next phase more than any issuance milestone will.
