0x5d92b1145d92…5d92b111

ConfirmedSecurity638 vB116 sat/vB3 min decode

September 2026 Crypto Hacks Top $766M, Worst Month of the Year

September 2026 hacks topped $766M, led by Bitget's $388M breach and a $320M Liquid Network exploit, per PeckShield and CertiK tallies.

Crypto Hacks September 2026 Cause $766M Losses - en.cryptonomist.ch
WitnessCrypto Hacks September 2026 Cause $766M Losses - en.cryptonomist.chAI-generated

Outputs

  1. September 2026 crypto losses exceeded $766 million, the worst month of the year

  2. PeckShield counted 55 incidents worth $766.5M; CertiK recorded 97 incidents worth $768.4M

  3. Bitget lost $388 million on September 24 across 19 unauthorized transfers; its $464M+ User Protection Fund will cover losses

  4. The Liquid Network exploit took $320 million, with over $270 million later recovered

  5. CertiK's 2026 dashboard shows 656 incidents and $2.68 billion in cumulative losses year-to-date

Crypto platforms lost more than $766 million to hacks and exploits in September 2026, making it the costliest month of the year for digital asset theft, according to independent tallies from blockchain security firms PeckShield and CertiK.

PeckShield counted 55 significant incidents totaling $766.5 million. CertiK recorded 97 incidents and estimated losses at $768.4 million. The two figures land less than $2 million apart despite different counting methodologies, a convergence that signals the month's breaches were systemic rather than a single outlier event.

CertiK summarized the situation in a statement published Wednesday: "September was a stark reminder of how quickly the threat landscape can shift."

What drove September's losses?

Two incidents dominated the month. The Bitget hack drained $388 million, while a separate exploit of the Liquid Network resulted in $320 million stolen. Together they account for roughly $708 million — the overwhelming majority of the total.

In the Bitget case, CEO Gracy Chen said the exchange identified 19 unauthorized transfers from portions of its hot and warm wallet systems during the afternoon of September 24. Cold wallets remained unaffected. Chen told CNBC that investigators traced IP addresses to VPN services previously associated with a North Korean hacking group, and that the attack's characteristics matched patterns from prior operations linked to that country.

Bitget's security team determined that an attacker compromised a backend wallet system, exploited it to falsify transfer data, and triggered the exchange's authorization-signing process. The company ruled out a private key breach. Bitget said its User Protection Fund, which holds more than $464 million, will cover the full amount lost.

The Liquid Network exploit followed a different trajectory. Of the $320 million taken, more than $270 million was later returned, according to reports cited by Cointelegraph — one of the few partial recoveries on record for a theft of this scale.

Which smaller platforms were hit?

Beyond the two headline breaches, several mid-sized incidents added to the month's toll:

  • Safe Wallet — $7.8 million lost
  • DCENT — $6 million lost
  • Duelbits — $5.9 million lost

Those three incidents contributed $19.7 million combined, a small fraction of the total but a signal that smaller platforms remain exposed to the same class of attacks.

How does September fit the 2026 picture?

CertiK's security dashboard shows 656 incidents across 2026 so far, with cumulative losses of $2.68 billion. September alone represents more than 25% of that yearly total, even though its 97 incidents account for only about 15% of all incidents CertiK recorded this year.

That gap between incident share and loss share is the defining feature of the month. A relatively small number of attacks inflicted outsized financial damage, driven almost entirely by Bitget and Liquid Network.

What are the operational lessons?

The September data points to persistent weaknesses in backend wallet infrastructure and third-party integrations rather than cryptographic failures. Bitget's attackers falsified transfer data through a compromised backend system, not by extracting private keys — an attack path that bypasses the assumptions most platforms build their security models around.

Bitget's response also demonstrated the operational value of insurance-style reserves. The exchange's User Protection Fund, at more than $464 million, exceeds the $388 million loss, allowing the company to make customers whole without tapping external capital. Liquid Network's partial recovery of over $270 million shows that on-chain tracing and negotiation can still claw back a substantial share of stolen funds when attackers move assets quickly.

The year-to-date total of $2.68 billion will keep climbing, and with three months remaining in 2026, the industry is on pace to approach the loss levels of prior peak hack years. Whether exchanges and wallet providers harden backend signing infrastructure before year-end will determine if October through December repeats September's pattern.

via en.cryptonomist.ch (Original)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles