BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Crypto Hack Losses Reach $2.68 Billion in 2026 as September…

Crypto hacks and exploits caused roughly $768 million in losses in September, making it the industry's costliest month of 2026, but the headline total was overwhelmingly concentrated in two i

AnonymousCryptoCompass newsroom
October 1, 2026
5 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for bitcoin coverage.

HK SFC Warns Public Against Ramp And Dump Scams Impersonating Stock Commentators

Crypto hacks and exploits caused roughly $768 million in losses in September, making it the industry's costliest month of 2026, but the headline total was overwhelmingly concentrated in two incidents: the Bitget security breach and the Liquid Network exploit. Blockchain security firm PeckShield counted 55 major incidents and approximately $766.5 million stolen during the month, while CertiK recorded 97 security incidents and $768.5 million in total losses. The difference reflects the firms' separate methodologies and definitions of reportable incidents rather than a material disagreement over the scale of the damage. CertiK's data puts third-quarter losses at $1.26 billion across 246 incidents, up 53.9% from $819.4 million in the second quarter. September alone accounted for roughly 61% of the quarter's gross losses.

Why Did September Losses Jump So Sharply?

Two attacks explain almost the entire increase. Bitget said unauthorized transfers from portions of its hot and warm wallet infrastructure ultimately totaled about $387.5 million, revising an initial estimate of $351.6 million. The exchange said attackers exploited a vulnerability in a third-party security product to obtain internal credentials and generate fraudulent withdrawal commands that bypassed existing risk controls. Cold wallets were unaffected, according to Bitget, which said user account balances remained intact. The exchange temporarily suspended withdrawals and began restoring them in stages from Sept. 28, with full withdrawal functionality for remaining assets, fiat currencies and peer-to-peer services scheduled for Oct. 2. The second major incident struck the Liquid Network on Sept. 6. A vulnerability in the Elements rangeproof verification cache allowed an attacker to create about 4,000 unbacked L-BTC and convert them through the network's peg-out process into native bitcoin. Blockstream estimated the exploit at roughly 4,000 BTC. The attacker later returned 3,400 BTC after identifying itself on-chain as a white-hat actor, while approximately 602 BTC remained subject to recovery efforts in Blockstream's latest detailed assessment.

Investor Takeaway

The September total looks like a broad deterioration in crypto security, but roughly 92% of the month's gross losses came from Bitget and Liquid alone. That concentration makes individual infrastructure failures more important than the raw incident count when assessing systemic risk.

How Much of the September Damage Was Actually Permanent?

Gross-loss figures can overstate the eventual economic damage because stolen assets are sometimes frozen, recovered or voluntarily returned. The Liquid case is the clearest example. CertiK initially valued the incident at approximately $318.7 million, but the return of 3,400 BTC materially reduced the unrecovered amount. Blockstream said about 602 BTC attributable to the unauthorized transactions remained outstanding as of its latest recovery update. CertiK's broader third-quarter figures show the same distinction. While gross losses reached $1.26 billion, adjusted losses after frozen and returned funds were approximately $869.6 million. Bitget's incident has a different financial structure. The exchange said its Protection Fund would absorb the financial impact rather than passing losses to customer balances. Bitget said on Sept. 30 that the fund had been replenished to more than $300 million after the breach. That does not make the incident economically costless. Protection funds are balance-sheet resources, and using them transfers the loss from customers to the platform rather than eliminating it.

Investor Takeaway

Gross hack totals should be separated from unrecovered losses. Returned assets reduced the Liquid exposure substantially, while Bitget absorbed its breach through its own protection mechanism. Recovery rates and who ultimately bears the loss matter as much as the initial theft figure.

What Do the Numbers Say About Crypto's Main Security Weakness?

CertiK classified exploits as the dominant attack vector in September, accounting for approximately $733.8 million, or 95.5% of total losses. Private-key compromises accounted for about $14.2 million, wallet compromises for $11.9 million and phishing for $6.2 million. That differs from the first half of the year, when wallet compromise was the largest financial threat. CertiK recorded $1.32 billion in Web3 losses during the first half of 2026, with wallet compromises responsible for $444.5 million. The changing distribution reinforces how volatile crypto security statistics can be. FinanceFeeds previously noted that May losses fell to only $68.3 million after April produced more than $600 million in attacks. A small number of large breaches can completely reshape monthly and quarterly comparisons. That concentration was already evident in the largest exploits of the first half of 2026, where infrastructure compromises and high-value wallet attacks increasingly outweighed smaller smart-contract failures.

Why Does September Matter Beyond the $768 Million Headline?

The Bitget and Liquid incidents affected different parts of the crypto stack. Bitget's breach involved exchange wallet infrastructure and a third-party security product, while Liquid's failure originated in consensus-related software used to validate confidential transactions. Together, they show that security exposure extends beyond smart-contract code. Exchanges depend on credential management, wallet architecture and third-party systems, while blockchain infrastructure can fail through vulnerabilities in lower-level protocol software. The industry's quarterly numbers therefore depend not only on how often attackers succeed, but on where they succeed. A single failure affecting an exchange wallet system or core blockchain component can outweigh dozens of smaller exploits.

Investor Takeaway

The strongest security indicator is not simply the number of hacks. Investors should watch where assets are custodied, how third-party systems interact with wallet infrastructure, whether losses can be isolated, and how quickly operators restore withdrawals and recover funds after an incident.