0x4d439c884d43…4d439c85
CertiK Tallies $766.4 Million in September Exploit and Phishing Losses
CertiK logged $766.4 million in September losses across 98 incidents, with Bitget ($387.5M) and Liquid Network ($318.7M) driving the year's worst month.
Outputs
CertiK reported $766.4 million in exploit and phishing losses for September 2026, the highest monthly figure of the year
Bitget ($387.5M) and Liquid Network ($318.7M) incidents account for roughly $706.2 million combined, before recoveries
CertiK's dashboard lists $273.2 million frozen or returned, cutting adjusted September losses to $495.3 million across 98 incidents
Crypto security firm CertiK reported roughly $766.4 million in exploit and phishing losses for September 2026, making it the worst month of the year by both dollar damage and incident count. Incidents at crypto exchange Bitget and the Liquid Network, a Bitcoin sidechain, accounted for the overwhelming majority of the total.
CertiK's incident ranking assigns $387.5 million to Bitget and $318.7 million to Liquid Network — about $706.2 million combined, according to The Defiant's calculation. The next-largest entry in the ranking, labeled Safe wallet users, came in at $7.8 million, underscoring how heavily two events skewed the month's aggregate figure.
"September has seen the highest recorded losses as well as the most incidents in 2026," CertiK said in its Sept. 30 alert.
The headline number measures losses before recoveries rather than the final damage borne by users. CertiK's live September dashboard lists $768.5 million across 98 security incidents, with $273.2 million frozen or returned. That brings adjusted, unrecovered losses down to $495.3 million — still the highest monthly figure of the year even after clawbacks.
September's alert exceeds each of CertiK's January-through-August month-end loss alerts. The closest comparable month was April, at $651 million, followed by January's $370.3 million. The July and August alerts reported $187.7 million and $214.7 million respectively, while February, March, May and June each came in below $100 million. These comparisons rely on the figures published in the monthly alerts rather than subsequently updated dashboard totals.
The September alert alone amounts to more than half of the $1.31 billion in losses CertiK reported for the first half of 2026 across 344 incidents in its Hack3D report.
Two Incidents, Two Failure Modes
The two largest September events stemmed from fundamentally different operational failures.
Bitget said attackers exploited a vulnerability in a third-party security product on Sept. 24, stole internal access credentials and forged withdrawal instructions. The exchange stated that private keys were not compromised and cold wallets were unaffected. Bitget said its Protection Fund would cover the financial impact without reducing user account balances. Its published recovery schedule calls for withdrawals of remaining coins, along with fiat and peer-to-peer services, to resume on Oct. 2.
Liquid Network disclosed a Sept. 6 vulnerability in its Elements software that allowed the creation of roughly 4,000 unbacked LBTC tokens. The exploiters converted those tokens into bitcoin through the network's withdrawal mechanism. In its Sept. 8 incident report, Liquid said 3,400 BTC had been returned to the federation's wallet on Sept. 7 — an illustration of why gross losses and unrecovered funds can differ substantially in CertiK's accounting.
The Bitget incident highlights a supply-chain exposure increasingly relevant to centralized exchanges: a vulnerability in a vendor's security tooling translated into internal credential theft and forged withdrawal flows without any direct compromise of private keys. The Liquid case, by contrast, struck at the core of the network's issuance integrity, allowing unbacked tokens to be redeemed for native bitcoin before the federation could contain the flaw.
The pattern also sharpens the year's risk profile. Two single events — one at an exchange, one at a Bitcoin sidechain federation — produced more than 90% of September's gross losses, while the remaining 96 incidents averaged far smaller amounts. That concentration suggests exchanges and bridge-style networks remain the highest-value targets, and that recovery capacity, whether through protection funds or federation cooperation, now materially determines net damage.
The immediate metric to watch is Bitget's Oct. 2 withdrawal resumption deadline: a smooth restart would validate the exchange's containment claims, while any delay would pressure its Protection Fund commitments and user confidence heading into the fourth quarter.
via x.com (Original)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles