Crypto Hacks Hit $766M in September, Worst Month of 2026

Crypto hacks causing $766 million in losses in September 2026.

Key Insights:

  • Security firms estimate that over $766 million has been stolen in September, the worst month for crypto losses so far this year.
  • The major exchange infrastructure and blockchain vulnerabilities of Bitget and Liquid seem to have been the biggest reasons behind the losses of September.
  • The impact was mitigated through recovery actions, as Liquid recovered 3,400 BTC and Bitget has been continuing to trace and freeze stolen assets.

The month of September has been the most expensive for crypto security incidents of the year, resulting in over USD 766 million in gross losses due to crypto hacks. PeckShield and CertiK suffered the same amount of losses, but their tracking methods differed, with most of the losses coming from the Bitget breach and the Liquid Network exploits.

PeckShield reported a total of $766.5 million from 55 major incidents, and CertiK estimated $768.4 million from 97 security events. September was thus a significant improvement over August where PeckShield had reported losses of around $136.3 million.

The two largest attacks also ranked among 2026’s biggest crypto security incidents. Bitget suffered a $387.5 million breach, while Liquid Network lost nearly $320 million before recovering most of the affected Bitcoin.

September losses accelerated after two major attacks

The month began with the Liquid Network exploit on September 6. An attacker exploited a vulnerability in the Elements codebase and created roughly 4,000 unbacked L-BTC.

Liquid said an error involving its rangeproof verification cache allowed the malicious transaction to pass validation. The attacker then used the network’s normal peg-out process to withdraw nearly 4,000 BTC.

The exploit reduced Liquid’s Bitcoin reserve from about 4,205 BTC to only 197 BTC. CertiK later valued the affected amount at approximately $318.7 million.

However, the incident produced an unusual recovery. The attacker returned 3,400 BTC on September 7 after communicating with Liquid through onchain messages.

Around 602 BTC remained outstanding after the return. Consequently, September’s reported losses reflect gross funds affected rather than the amount that remains permanently missing.

  • Bitget accounted for roughly half of September’s reported losses.
  • Liquid’s attacker returned most of the Bitcoin taken during the exploit.
  • Security firms still counted the original Liquid incident in their monthly totals.

Bitget breach became the month’s largest incident

Bitget suffered the largest September attack on September 24 after an attacker gained access to parts of its hot and warm wallet infrastructure.

The exchange initially estimated the loss at $351.6 million. It later revised the figure to approximately $387.5 million after investigators traced additional assets to attacker-controlled addresses.

The affected assets included ETH, XRP, USDT, USDC, ZEC, BNB, AVAX and TRX. Bitget said its cold wallets and private keys remained secure throughout the incident. Mandiant and SlowMist later investigated the breach. Their findings pointed to compromised third-party security software and unauthorized access to the exchange’s wallet environment.

The attacker subsequently moved funds across networks and conversion services. Tracking efforts identified transactions involving THORChain and other tools, while AMLBot traced roughly four BTC into a Wasabi CoinJoin transaction.

Bitget gradually restored withdrawals for affected assets. The exchange also continued efforts to freeze and recover stolen funds with outside investigators and blockchain companies.

Security losses climbed across the wider sector

September’s crypto hacks pushed total 2026 losses to approximately $2.68 billion, according to CertiK. Its figures cover 656 security incidents recorded through the year. The September surge also lifted third-quarter losses above $1.2 billion. CertiK reported that Q3 losses increased 53% from the $819.4 million recorded during the second quarter.

The incidents extended beyond centralized exchanges and blockchain networks. Safe Wallet, DCENT and Duelbits suffered losses of approximately $7.8 million, $6 million and $5.9 million.

Attackers also targeted bridges, wallets, decentralized applications and smart-contract infrastructure. Phishing accounted for more than 11% of Q3 incidents, according to CertiK, while scams represented only a small portion of reported security events.

The concentration of losses remained striking. Bitget and Liquid alone represented most of September’s stolen value, despite dozens of other incidents occurring during the month.

September exposes persistent infrastructure risks

The numbers from September show that hacks in the cryptocurrency world keep taking advantage of weak spots in the digital money industry. A problem at Bitget happened because their security system was broken and a problem at Liquid started because of a mistake in software checking.

The difference between these two events shows how different ways hackers can attack. Things like access, to wallets, outside software, bridge systems and the way contracts work can all cause losses.

The final impact was also affected by recovery efforts. Liquid managed to recover 3,400 BTC, and Bitget has continued its investigation into the breach, resulting in asset freezes and tracing efforts.

Conclusion

The estimated monthly losses have peaked at $766.5 million to $768.4 million as Crypto hacks hit the highest level in 2026 during September. The Bitget breach demonstrated the risks surrounding exchange infrastructure, while Liquid showed how software flaws can create large losses within decentralized networks.

CertiKs $2.68 billion annual number shows that September was part of a trend of higher security losses. The month also proved that recovery efforts can significantly affect the financial result without taking the security incident out of industry reports.

Brenda Mary

Brenda Mary is a cryptocurrency journalist, SEO analyst, and editor with over 3 years of experience in blockchain, digital assets, and crypto market analysis. She has contributed to leading platforms including Crypto.news, Cryptopolitan, The Coin Republic, and Analytics Insight.
At CoinRaftar, she covers crypto news, market trends, and Web3 developments, simplifying complex topics into clear, reader-friendly insights.
Bachelor’s in International Business Management, University of Nairobi.
https://www.linkedin.com/in/brenda-mary-248b2422b/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top