0x3d50faff3d50…3d50fafc

ConfirmedSecurity516 vB17 sat/vB3 min decode

Crypto Hacks Surpassed $768M in September, 2026's Worst Month

September crypto losses topped $766M across 55-97 incidents, per PeckShield and CertiK. Bitget lost $388M and Liquid Network $320M, with $270M later returned. 2026 losses now total $2.68B.

Crypto hacks top $768M in September, worst month of 2026
WitnessCrypto hacks top $768M in September, worst month of 2026AI-generated

Outputs

  1. September 2026 crypto hack losses exceeded $766M, the worst month of the year

  2. PeckShield counted 55 incidents ($766.5M); CertiK counted 97 incidents ($768.4M)

  3. Bitget lost $388M; Liquid Network lost $320M, with over $270M later returned

  4. CertiK's dashboard shows 656 incidents and $2.68B in total losses in 2026

  5. Other September incidents: Safe Wallet ($7.8M), DCENT ($6M), Duelbits ($5.9M)

Crypto platforms lost more than $766 million to hacks and exploits in September, making it the worst month of 2026 for security incidents, according to independent estimates from blockchain security firms PeckShield and CertiK.

PeckShield counted 55 major incidents resulting in $766.5 million in stolen funds. CertiK recorded 97 incidents and put losses at $768.4 million. Both firms reported a significant increase compared with August, with no sign that incident frequency is slowing.

Two events dominated the month. The Bitget hack drained $388 million from the exchange, and a separate exploit hit the Liquid Network for $320 million. More than $270 million of the Liquid Network funds was later returned, according to reports. Even after that partial recovery, both incidents rank among the largest crypto thefts of the year.

What drove the losses?

The September total was not spread evenly across the ecosystem. The two largest incidents accounted for roughly $708 million of the losses — more than 90% of the monthly figure by either firm's count.

The remaining incidents clustered in the mid-single-digit millions:

  • Safe Wallet: $7.8 million
  • DCENT: $6 million
  • Duelbits: $5.9 million

The concentration matters for how firms allocate security spending. A month defined by two outsized breaches points to sophisticated, targeted attacks on large custodial and infrastructure targets rather than a broad rise in small-scale exploits. SlowMist has traced Bitget hack activity to a zero-day exploit dated Aug. 31, indicating the attackers had preparation time before the September theft.

What are the firms saying?

CertiK framed the month as a warning about how rapidly attacker capabilities evolve. "September was a stark reminder of how quickly the threat landscape can shift," the firm said in a statement Wednesday.

The divergence between the two firms' incident counts — 55 versus 97 — reflects differing methodologies for what qualifies as a "major" incident, yet the loss estimates landed within $2 million of each other. That convergence gives the headline figure unusual credibility for an industry where damage assessments often vary widely.

How does September fit the 2026 trend?

CertiK's security dashboard shows 656 security incidents so far in 2026, with total losses of $2.68 billion. September alone contributed more than a quarter of the year-to-date damage.

That ratio has direct operational consequences. Exchanges and network operators facing losses of this scale typically face pressure to accelerate migrations to multisig custody, tighten withdrawal controls and expand bug bounty programs — measures that carry real cost and friction for users.

For the affected platforms, the math is stark: recovering $270 million still leaves the Liquid Network exploit among the year's largest thefts, and Bitget's $388 million loss remains unrecovered based on current reporting.

What comes next?

With three months left in 2026 and losses already at $2.68 billion, the industry is on pace for one of its worst security years on record. Expect exchanges to face heightened scrutiny from regulators and insurers as incident reports accumulate — and watch whether October's figures confirm whether September was an outlier or the new baseline for attacker sophistication.

via x.com (Original)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles