Crypto hacks have caused more than $766 million in gross losses during September, making it the costliest month of 2026 as the Bitget and Liquid Network incidents dominated the total. Summary
Crypto hacks have caused more than $766 million in gross losses during September, making it the costliest month of 2026 as the Bitget and Liquid Network incidents dominated the total.
Summary
- September crypto hacks caused $766.5 million in losses across 55 major incidents, according to PeckShield.
- CertiK counted 97 September incidents and estimated $768.4 million in losses across the crypto sector.
- Bitget confirmed $387.5 million reached attacker-controlled addresses after its September 24 hot-wallet security breach occurred.
- Liquid’s attacker returned 3,400 BTC after exploiting a bug that created approximately 4,000 unbacked L-BTC.
- CertiK reports 656 security incidents and $2.68 billion in crypto losses during 2026 so far.
PeckShield reported 55 major security incidents with approximately $766.5 million stolen during the month, while CertiK counted 97 incidents and put losses at $768.4 million. The firms use different tracking methods and did not publish identical incident counts, but their estimates of total stolen value were separated by less than $2 million.
September’s figure was far above August. PeckShield had counted 50 major attacks worth roughly $136.3 million during August, according to crypto.news coverage of the previous monthly hack report. CertiK’s dashboard placed August losses at $220.3 million under its own methodology.
You might also like: Bitget brings back USDT withdrawals after $387M hack
Bitget accounted for the largest September loss
Bitget’s Sept. 24 breach was the biggest single incident included in the September total. The exchange confirmed that approximately $387.5 million in crypto reached attacker-controlled addresses after investigators expanded an initial estimate of $351.6 million.
The breach affected portions of Bitget’s hot and warm wallet infrastructure across Ethereum and other EVM networks, XRP Ledger, Zcash and Tron. Assets involved included ETH, XRP, USDT, USDC, ZEC, BNB, AVAX and TRX. Bitget said its cold wallets and private keys were not compromised.
Independent investigations by Mandiant and SlowMist later found that compromised third-party security software gave the attacker unauthorized access to Bitget’s wallet environment. Bitget said the flaw was identified and fixed after the attack.
Some stolen assets began moving through cross-chain services after the breach. As covered in crypto.news’ tracking of the Bitget attacker, one wallet converted roughly 2,390 ETH into 75.2 BTC through THORChain. AMLBot separately traced around four BTC into a Wasabi CoinJoin transaction.
Bitget has since restored BTC, ETH and USDT withdrawals. Its latest proof-of-reserves report showed a 131% total reserve ratio across 19 covered assets, while the company said its Protection Fund had been replenished above $300 million on Sept. 30.
Liquid’s $319M exploit had a very different outcome
Liquid Network suffered the other major September attack on Sept. 6, when a vulnerability in the Elements codebase allowed an attacker to create roughly 4,000 L-BTC without matching Bitcoin backing.
Liquid Network reported that an error in its rangeproof verification cache allowed a malicious transaction to pass validation. The attacker then used Liquid’s normal peg-out process to withdraw close to 4,000 real BTC, reducing the federation’s Bitcoin reserve from approximately 4,205 BTC to 197 BTC.
CertiK independently placed the affected amount at 3,998.5 L-BTC, valued at approximately $318.7 million when the exploit occurred.
Unlike most large thefts, most of the Bitcoin was returned quickly. After communicating with the Liquid team through onchain messages and negotiations, the attacker returned 3,400 BTC on Sept. 7. Liquid’s later assessment said approximately 602 BTC remained outstanding.
The recovery means September’s $766 million-$768 million figure should be read as gross value affected by security incidents, not the amount still permanently missing. The returned 3,400 BTC does not remove the original Liquid exploit from security firms’ monthly incident totals.
As crypto.news reported after the recovery, roughly 85% of the Bitcoin withdrawn from Liquid had been returned within a day. At the time of the repayment, the recovered coins were worth around $269 million.
Smaller crypto hacks added millions to September’s total
Outside Bitget and Liquid, CertiK identified several smaller losses during September. Safe Wallet suffered an estimated $7.8 million incident, while DCENT and Duelbits recorded losses of around $6 million and $5.9 million, respectively.
CertiK’s 2026 data now covers 656 security incidents and roughly $2.68 billion in losses, according to figures reported alongside its September tally. September alone became the year’s largest month by estimated stolen value.
The figures follow an already active year for attackers. Before September, crypto.news research into 2026 DeFi hacks found at least $1.3 billion had been lost during the first eight months, with compromised credentials and private keys playing a large role in several major incidents.
September’s two largest attacks used different paths. Bitget said the attacker obtained access through compromised third-party security infrastructure and forged wallet withdrawal commands. Liquid’s exploit came from a software validation flaw that permitted unbacked L-BTC to be created.
CertiK described September as a reminder of how quickly the security environment can change, while its incident-level research identified the Liquid flaw as an ambiguous cache-key encoding problem in Elements’ rangeproof verification code.
Recovery work continues after September’s biggest hacks
Bitget’s fund-tracing operation remains active. Mandiant and SlowMist are supporting the investigation, while the exchange is offering rewards tied to freezing and recovering stolen assets. Bitget has set a 5% bounty for qualifying assistance that directly results in assets being frozen or recovered.
Circle and Tether had frozen roughly $318,000 in stablecoins linked to the Bitget incident during the first days of the investigation, according to crypto.news coverage of the recovery bounty.
For Liquid, Blockstream deployed an emergency patch after halting the network and released Elements v23.3.4 with a hardened proof-cache implementation. Block production resumed on Sept. 9 after the affected chain was corrected, though peg operations remained suspended at that stage.
Liquid subsequently began an independent security audit of Elements v23.3.4 and work to replace peg-out authorization entries before restoring regular withdrawals. Crypto.news reported that peg-outs remained suspended as of Sept. 29, with the network yet to provide a fixed reopening date.
Bitget’s remaining token, fiat and P2P withdrawals are scheduled to resume at 08:00 UTC on Oct. 2 under its phased recovery plan.
Read more: Why is Stacks price up 20% as Muneeb Ali becomes CEO?