September was the costliest month for crypto security incidents in 2026 by a wide margin, with two independent trackers putting gross losses at roughly 766 to 768 million USD. PeckShield reported 55 major security incidents with approximately 766.5 million USD stolen, while CertiK counted 97 incidents and estimated 768.4 million USD in losses across the sector. The firms use different tracking methods and did not publish identical incident counts, yet their totals landed less than 2 million USD apart, an unusually tight agreement between competing methodologies.
The scale of the jump is the real story. PeckShield’s figure represents a roughly 462 percent month-over-month increase from August, which it counted as 50 major attacks worth about 136.3 million USD. Under CertiK’s methodology, August losses stood at 220.3 million USD. Either way, September delivered a step-change in damage, driven almost entirely by two incidents that together account for the overwhelming majority of the month’s losses.
Bitget: 387.5 Million USD Confirmed Gone
The largest single event was the Sept. 24 breach of Bitget. The exchange has now confirmed that approximately 387.5 million USD in crypto reached attacker-controlled addresses, an upward revision from the initial estimate of 351.6 million USD as investigators expanded their accounting. The breach affected portions of Bitget’s hot and warm wallet infrastructure across Ethereum and other EVM networks, XRP Ledger, Zcash and Tron, with assets involved including ETH, XRP, USDT, USDC, ZEC, BNB, AVAX and TRX. The company has maintained that its cold wallets and private keys were not compromised.
Independent investigations by Mandiant and SlowMist concluded that compromised third-party security software gave the attacker unauthorized access to Bitget’s wallet environment, a supply-chain failure rather than a broken on-chain protocol. Bitget says the flaw has been identified and fixed.
The aftermath has played out onchain. One wallet linked to the attacker converted roughly 2,390 ETH into 75.2 BTC through THORChain, while AMLBot separately traced around four BTC into a Wasabi CoinJoin transaction, classic laundering patterns that make recovery complicated. On the recovery-of-a-different-kind front, Bitget has restored BTC, ETH and USDT withdrawals, released a proof-of-reserves report showing a 131 percent total reserve ratio across 19 covered assets, and said its Protection Fund was replenished above 300 million USD as of Sept. 30.
Liquid Network: 320 Million USD Exploited, 85 Percent Returned Within a Day
The month’s second-largest incident could not have had a more different ending. On Sept. 6, Liquid Network suffered an exploit rooted in a vulnerability in the Elements codebase, where an error in the rangeproof verification cache allowed a malicious transaction to pass validation. The attacker used the bug to create roughly 4,000 L-BTC without matching Bitcoin backing, then pushed the unbacked tokens through Liquid’s normal peg-out process to withdraw close to 4,000 real BTC. The federation’s Bitcoin reserve fell from approximately 4,205 BTC to 197 BTC. CertiK independently placed the affected amount at 3,998.5 L-BTC, worth approximately 318.7 million USD at the time.
Then came the part almost nobody expects in a nine-figure hack: the attacker talked, and then gave the money back. After onchain messages and negotiations with the Liquid team, the attacker returned 3,400 BTC on Sept. 7, worth around 269 million USD at the time, roughly 85 percent of the withdrawn coins within a day. Liquid’s later assessment put the remaining outstanding amount at approximately 602 BTC. The episode resembles a white-hat resolution wearing a black-hat mask, though the motivation remains publicly unexplained.
One important caveat for reading the monthly totals: the 766 to 768 million USD figures represent gross value affected by security incidents, not value permanently lost. With 3,400 BTC already returned from the Liquid exploit, the net damage is materially lower than the headline, even though security firms correctly keep the original incident in their monthly counts.
A Grim Year Overall
Zoom out and 2026 is tracking badly. CertiK reports 656 security incidents and 2.68 billion USD in crypto losses so far this year. September alone contributed more than a quarter of that total. Beyond the two giants, CertiK identified a long tail of smaller losses through the month, including an estimated incident at Safe Wallet, phishing campaigns and protocol-level exploits that each added millions to the tally but none of which individually approached the scale of the leaders.
The pattern across the month also carries a lesson about where risk actually lives. Neither of September’s two headline failures was a broken consensus mechanism or a novel cryptographic break. Bitget’s loss traced to compromised third-party security software inside the exchange’s own environment, and Liquid’s loss traced to a subtle implementation bug in a verification cache. In both cases, the crypto industry’s weakest links were the human-built layers wrapped around otherwise functioning systems.
What to Watch in October
Three indicators will show whether September was an outlier or a trend. First, Bitget’s attacker still controls hundreds of millions in stolen assets; further movement through cross-chain bridges, mixers or exchanges would test the industry’s freeze coordination. Second, Liquid’s remaining 602 BTC outstanding is small enough that a negotiated return remains plausible, and any movement should be visible onchain. Third, watch whether the exchange software supply chain gets the audit attention the Bitget post-mortem implies it needs, because the next variant of a compromised security vendor will not be stopped by better blockchain code.
The month’s final accounting may soften as recoveries land, but the message of September 2026 is already fixed: gross hack losses nearly quintupled in a single month, and the industry’s security perimeter is still defined by its most mundane software dependencies.
Price snapshot at publication (Binance, 17:01 UTC, Oct. 1, 2026): BTC 84,226 USD, ETH 2,682.50 USD, SOL 117.25 USD.
mandiant pointing at compromised third party security software is the grim part. perfect keys and you still get cooked by a vendor
^ this. the attack surface moved up the stack years ago, cold wallet purists never got the memo
768 million lost in one month and 387.5 million of it is a single exchange keeping funds in hot and warm wallets across six chains. Bitget already revised that figure up once.
The revision from 351.6 to 387.5 million is what worries me. If the accounting moved that much within a week, the real figure is a moving target.
462 percent jump from august and almost all of it from two incidents. one brutal month at bitget and liquid, not a sector wide breakdown
2,390 eth through thorchain into 75 btc plus a wasabi join. they will be washing that for months
Liquid getting 3,400 BTC back within a day because the attacker negotiated is the strangest silver lining of 2026. Roughly 85 percent recovered just by talking.
97 incidents and two of them carry most of the damage. There is a long tail of small breaches nobody bothers reporting sitting under those whales.