Between July and September 2026, attackers pulled roughly $1.26 billion out of the crypto market. The figure comes from the security firm CertiK, which counted 247 security incidents in the t
Between July and September 2026, attackers pulled roughly $1.26 billion out of the crypto market. The figure comes from the security firm CertiK, which counted 247 security incidents in the third quarter. That means almost half as much drained away in three months as in the whole year to date, for which CertiK arrives at around $2.68 billion.
For you as an investor in Germany, this is not an abstract statistic. The big cases of the quarter did not hit exotic niche projects but one of the largest trading platforms in the world and an established sidechain. This piece puts the figures in context, separates the two competing counts from one another, and shows where you can genuinely check your own custody.
What CertiK counted for the third quarter of 2026
CertiK keeps a running tally of attacks on blockchain protocols, trading venues and wallet infrastructure. For the third quarter of 2026 the firm puts the damage at around $1.26 billion from 247 incidents. On the same count, the second quarter stood at $819.4 million from 219 incidents. The total has therefore risen by a good half, the number of cases by just under thirteen percent.
That ratio is the real finding. There were not substantially more attacks, but the successful ones were markedly larger. Average damage per incident climbed from around $3.7 million to about $5.1 million. Anyone who leaves crypto assets on a platform shares their risk with every other customer of that same platform, and that is precisely where the large sums sit.
What CertiK counts as a security incident
A security incident in this tally is any case in which crypto assets leave their owner without the consent of the person entitled to them. That covers three very different things: the exploit, meaning the abuse of a flaw in a protocol's program code; key theft, where attackers obtain private keys or approval rights; and fraud, where users are talked into granting access themselves. Price losses, insolvencies and frozen withdrawals do not count.
The distinction matters because it determines the countermeasure. Against a flaw in the code of someone else's protocol there is little you can do as a user other than avoid the protocol. Against key theft and approval fraud you can do a great deal.
September 2026: 99 incidents and the highest monthly loss of the year
September carried the bulk of the quarterly damage. Depending on the count, between $766 million and $769 million drained away, spread across 99 larger incidents. That is the highest monthly figure of 2026 and at the same time the highest case count since February 2025. Against August, which was unusually quiet, it amounts to a rise of around 462 percent.
The previous peak month of the year was April at a little over $648 million, driven at the time by the attack on KelpDAO. September has surpassed that figure even though the year had been regarded as comparatively calm until then.
CertiK itself framed the month on its own channel in these terms: September was a clear reminder of how quickly the threat picture can shift; with losses and case numbers at the year's high, the month underlined that security is needed at every level. The assessment comes from the firm that also collects the figures, which is worth keeping in mind, because CertiK sells audits of program code.
Bitget and Liquid Network: the two largest single cases of the quarter
Two cases together account for almost half of September's damage. Around $387.5 million fell on the trading platform Bitget. At Liquid Network, a sidechain built on Bitcoin, it was around $320 million, of which about $285 million flowed back according to the analytics firm Chainalysis.
Bitget then reopened withdrawals in stages: first Bitcoin, then Ether, then stablecoins, and finally the remaining routes. That a platform of this size needs several days to restore normal operation is the practical part of the news. For that period you cannot reach your balance, regardless of whether your own account was affected at all.
The $1.26 billion is a gross figure: what is recorded is what drained away, not what remained lost in the end. In the Liquid Network case the large majority came back, which noticeably lowers the quarter's actual net damage. Returns like this happen when attackers cannot move stolen funds because analytics firms and trading venues flag the addresses. Do not rely on it: in most cases the money stays gone.

In most of the quarter's large cases it was not the encryption that broke, but the access in front of it.
Two counts, two totals: $766 million to $769 million in September
Two numbers are in circulation for the September figure. CoinDesk cites CertiK for $768.5 million, while other analyses of the same data arrive at $766.49 million. The gap of around $2 million sounds wide, but at a total of this order of magnitude it is a rounding and cut-off effect.
Discrepancies like this arise because damage totals are valued in dollars while the stolen assets are held in cryptocurrencies. Depending on whether the price at the moment of the attack, at month end or at the time of the analysis is applied, the result shifts. Late reports add to it: an incident on September 29 may only be fully quantified in October.
For you that means taking such numbers as an order of magnitude, not as a measurement. The statement that September was the worst month of the year holds. The second decimal place does not.
Stolen keys instead of broken cryptography: the most common route of attack
The notion that cryptocurrencies are being cracked misses the reality. The underlying encryption holds. What breaks, regularly, is the layer in front of it: the management of keys, the approval of transactions, employee access to internal systems. We have set out this finding in detail for DeFi hacks; it applies to centralised platforms in exactly the same way.
A private key is the string of characters that allows crypto assets at an address to be moved. Whoever holds it controls the assets, with no password, no confirmation prompt and no way of reversing the entry. That is precisely why attackers go for it and not for the mathematics behind it.
Phishing and approval rights
The second major route runs through approvals. When you use a decentralised application, you grant its smart contract the right to move tokens out of your wallet. That approval stays in place until you withdraw it, including long after you have stopped using the application. An unlimited approval to a contract that is later compromised is an open door.
In practice that means granting approvals with an amount limit rather than without one, and clearing out old approvals regularly. The common block explorers offer an overview of the rights you have granted.
Centralised exchange or your own wallet: where your risk actually sits
The quarterly figures show both risks side by side. If your coins sit on a trading platform, you carry its counterparty risk: if it is attacked, your balance depends on its reserve cover and on its determination to absorb the damage. If you hold the assets yourself, you carry the risk alone, and a lost key is final, but no outside incident can reach you.
There is a middle road. Anyone who trades regularly leaves the trading balance on the platform and withdraws the long-term holding. For the part that is withdrawn, a hardware wallet is the usual instrument; which devices differ in what is set out in our hardware wallet comparison. What matters is less the model than whether you keep the recovery words safely and offline.
What self-custody takes off your hands and what it does not
Self-custody, meaning holding assets under your own responsibility, takes the counterparty risk off your hands. It does not take the fraud risk off your hands. Anyone who is induced to sign a malicious transaction loses their coins from a hardware wallet too. The device protects the key, not the decision.

Bridges and cross-chain services connect separate networks, and in doing so they form an attack surface of their own.
MiCA and BaFin: the duties a provider in Germany has to meet
Since July 1, 2026 the EU regulation on markets in crypto assets, MiCA for short, has applied without restriction; that was the day the transition period ended for providers previously operating under national law. Anyone who holds crypto assets for customers in Germany or offers trading has since needed an authorisation and is supervised by BaFin or another European authority.
For custody, that above all means an obligation to segregate: customer holdings are to be kept separate from the provider's own assets so that they do not fall into the estate if it becomes insolvent. Added to that are requirements for internal controls and for documenting key management. We have put together an overview of which duties apply in detail.
An authorisation is not insurance against attacks, and some of the quarter's cases involved regulated houses. What it does change is the starting position when something happens: there is a competent supervisor, a legal entity you can get hold of, and documented segregation of holdings. Which providers are authorised for the German market is shown by our overview of regulated crypto exchanges.
Compensation after a hack: the legal position in Germany
Whether you get money back after an attack hangs on two questions: where were the assets held, and who is answerable for the failure? If they were with an authorised custodian, its contractual and regulatory duties apply, and the segregation of customer holdings is meant to ensure that your claim does not founder on the provider's insolvency. If they were in your own wallet, there is no one to claim against except the perpetrator.
In practice, large platforms have often made good losses out of their own funds in recent years, voluntarily and as a business decision, not because of a statutory guarantee. There is no deposit protection scheme for crypto assets of the kind that covers bank balances. Plan with the way you split your holdings, then, rather than with a refund.
For tax purposes a theft is not a disposal. Anyone affected should nevertheless document the incident without gaps: the time, the addresses involved, the correspondence with the provider, the report to the police. Without those records, neither a civil claim nor a tax treatment can be substantiated later on.
Cross-chain bridges as an attack surface: the NEAR Intents case
The quarter ended with a case that shows the weak point well. The cross-chain service NEAR Intents confirmed an attack on its infrastructure on October 1, 2026 with damage of around $3.8 million; deposits and withdrawals across twelve networks were affected. The service announced that it would compensate those affected in full. The price of the associated token fell back sharply as a result; the context for that is on our NEAR forecast page, and we described the sequence of events in detail on October 1.
A cross-chain bridge is a service that moves assets between separate blockchains. Because the networks do not know one another, the bridge locks the assets on one side and issues an equivalent on the other. That intermediate step is a place of custody in its own right, and therefore a worthwhile target.
What that means for the way you use bridges
Bridges are not a storage place. Anyone moving assets across chains should complete the process and then take the assets to where they are meant to sit. A balance left for weeks in a bridge contract or an intent service carries a risk with no return to match it.
Crypto Hacks: How to Proceed Now
- Separate your trading balance from your long-term holding. Leave on the platform only what you will actually move in the coming weeks. The rest you withdraw into custody of your own; the differences between the devices are set out in the hardware wallet comparison.
- Check your provider's authorisation. Look up whether your trading venue holds a MiCA authorisation for the German market and who supervises it. You will find an overview sorted by supervisory status among the regulated crypto exchanges.
- Clear out your approvals. Go through the token approvals your wallet has granted and withdraw what you no longer need. The duties that come on top on the provider's side are set out in our overview of the MiCA licensing obligations.
(As of October 2, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)