0x745203f07452…745203f3
CertiK: Bitget's $388M Hack Drives $1.26B in Q3 Crypto Losses
CertiK reports $1.26B in Q3 crypto security losses across 247 incidents, with Bitget's $387.5M hot-wallet exploit accounting for roughly 31% of the total. September alone saw $769M.

Outputs
CertiK recorded $1.26B in Q3 crypto security losses across 247 incidents, up 53.9% from Q2's $819.4M.
Bitget's $387.5M hot-wallet hack on Sept. 24 accounted for roughly 31% of the quarter's losses.
September alone logged ~$769M in losses across 99 incidents, with $273M subsequently frozen or returned.
Liquid Network ($319M on Sept. 6), Tectonic ($120M), and the Coldcard theft ($112.7M) were the next-largest incidents.
SlowMist traced related Bitget hack activity to an Aug. 31 zero-day exploit, indicating roughly 24 days of pre-detection access.
CertiK recorded $1.26 billion in losses from crypto security incidents during the third quarter across 247 separate events, a 53.9% increase from the $819.4 million reported in Q2. The figure marks one of the largest quarterly tallies on record under the blockchain security firm's methodology and reflects a 13% rise in incident count, up from 219 in the prior period.
Bitget's $387.5 million hot-wallet hack was the quarter's single largest incident, accounting for roughly 31% of all losses. The exchange detected unauthorized transfers from some of its hot wallets on Sept. 24 and suspended withdrawals. Bitget said attackers exploited a vulnerability in a third-party security product to obtain internal credentials and forge withdrawal commands.
How did September shape the quarter?
September alone accounted for approximately $769 million in losses across 99 incidents, making it the worst month of the period. Roughly $273 million of that total was subsequently frozen or returned, leaving an adjusted loss figure of $495.3 million for the month. Exploits drove $734 million of the September total — nearly 96% of the monthly figure — across 58 incidents, with phishing, rug pulls and exit scams making up the remainder.
Which other exploits defined the quarter?
- Liquid Network: $319 million exploit on Sept. 6
- Tectonic: $120 million
- Coldcard theft: $112.7 million
The three incidents together account for roughly $551 million in losses outside the Bitget case.
What does the Bitget case reveal about operational risk?
The incident underscores a recurring attack vector in centralized exchange infrastructure: the compromise of third-party security tooling. Bitget attributed the breach to a vulnerability in a third-party product, which the company said allowed attackers to obtain internal credentials and forge withdrawal commands. SlowMist has traced related wallet activity to a zero-day exploit dated Aug. 31, indicating that attackers maintained access to the environment for nearly four weeks before the Sept. 24 detection. The roughly 24-day dwell time illustrates how third-party product compromises can extend the window of exposure well beyond the moment of initial intrusion.
What is the recovery outlook?
The $273 million frozen or returned in September reflects intervention by exchange and protocol teams, coordinated blocking of stolen funds, and partial returns to victims. Bitget has not disclosed whether any portion of the $387.5 million was recovered following the Sept. 24 detection. The Liquid Network case has produced limited public updates on asset tracing since the initial Sept. 6 disclosure, leaving a substantial portion of the quarter's $1.26 billion total at risk of remaining unrecovered.
What does the trajectory signal for risk managers?
The quarter-over-quarter rise in both losses and incident count — 247 events versus 219 in Q2 — points to a broadening of attack surfaces as total value locked across centralized venues grows. The concentration of losses in a small number of high-value exploits, with the top four incidents together exceeding $939 million, also suggests that tail-risk preparedness remains a board-level concern for custodians operating across multiple chains. Adjusted loss figures in forthcoming CertiK reports will depend on how much of the frozen $273 million from September is ultimately returned to victims, and recovery proceedings in the Bitget, Liquid Network and Tectonic cases are expected to extend into the fourth quarter.
via certik.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
439 articles