September 2026 has gone down as the most damaging month of the year for crypto security, with hackers stealing approximately $766.5 million across 55 major attacks — a roughly 462% increase f
September 2026 has gone down as the most damaging month of the year for crypto security, with hackers stealing approximately $766.5 million across 55 major attacks — a roughly 462% increase from August’s total of $136.3 million, according to blockchain security firm PeckShield.
The staggering jump was driven almost entirely by two incidents: the Bitget exchange hack and the Liquid Network breach, which together accounted for the overwhelming majority of the month’s losses.
The Numbers Behind the Record Month
PeckShield confirmed the scale of September’s damage directly on X: “In Sep. 2026, the crypto industry experienced 55 major hacks, resulting in total losses of $766.49M — a ~462% month-over-month increase from August’s $136.3M.” The firm noted that two incidents in particular reshaped the year’s overall ranking of major crypto thefts:
“The #Bitget incident (~$387M) and #LiquidNetwork (~$320M, with $285M returned) have jumped to #1 & #2 among the largest crypto thefts of the year to date, surpassing the #Drift and #KelpDAO/#LayerZero exploits.”
Top 10 Hacks of September
According to PeckShield’s data, September’s ten largest incidents were:
– Bitget — $387 million – Liquid Network — $320 million ($285 million returned) – MEV bot “yoink” front-run — $7.81 million (returned) – Duelbits — $7 million – Payment Processor V2 — $6.6 million ($3.4 million returned) – D’CENT Wallet — $6.57 million – Astroport — $4.9 million – Drop — $4.4 million – Nostra Finance — $3.5 million – Nomic nBTC Bridge — $3.15 million
The Bitget Hack: September’s Largest Single Incident
Bitget, one of the world’s top-five cryptocurrency exchanges by scale, confirmed on September 24 that its security systems had detected unauthorized transfers involving a limited number of hot wallets. The exchange’s initial assessment put the damage at roughly $351.6 million; after identifying additional stolen assets on the Zcash and Tron networks, Bitget revised the total upward to approximately $387.5 million, matching PeckShield’s figure.
According to Bitget’s own investigation, the attacker exploited a vulnerability in a third-party security product the exchange used to obtain high-level internal credentials, then used those credentials to send fraudulent withdrawal commands directly to Bitget’s wallet system — bypassing the platform’s risk controls without ever compromising private keys or touching cold wallet storage. Bitget’s CEO, Gracy Chen, said preliminary evidence pointed toward North Korea-linked hackers, though she emphasized that attribution had not been confirmed with full certainty. The exchange’s User Protection Fund, which held 5,500 BTC (roughly $464 million) at the time, is covering the losses, and Bitget began a phased restoration of withdrawals starting September 28.
The Liquid Network Incident: A Partial Recovery
The second-largest incident of the month involved Liquid Network, the Bitcoin layer-2 sidechain operated by a global federation of crypto exchanges and financial institutions. Roughly 4,000 BTC, worth approximately $320 million, was withdrawn from the network’s federation wallet by parties who identified themselves on-chain as “white hats.” Unlike the Bitget incident, a substantial portion of the Liquid Network funds — approximately $285 million — was ultimately returned, meaningfully limiting the incident’s net financial impact compared to its initial scale.
A Brutal Year Overall
September’s totals cap off what has already been an exceptionally difficult year for crypto security broadly. Earlier in 2026, researchers tracking on-chain attacks estimated first-half losses at roughly $970 million to $1 billion across more than 200 separate incidents, according to data compiled by firms including TRM Labs and Immunefi. The year’s previous largest single incidents — the April exploits of Drift Protocol (approximately $285 million) and KelpDAO (approximately $292 million) — were both attributed to North Korea-linked threat actors, and both have now been surpassed by Bitget and Liquid Network in September’s rankings.
Beyond the headline incidents, 2026 has produced a steady drumbeat of smaller but still significant breaches: Coldcard hardware wallets lost roughly $89 million to a seed-generation flaw, Cronos-based lending protocol Tectonic lost approximately $75 million to a price manipulation attack, Ostium lost about $18 million to an oracle exploit, and hardware wallet makers SafePal and Trezor both disclosed customer data leaks affecting tens of thousands of users, even though no funds were directly stolen in those specific incidents.
What September’s Numbers Reveal
The concentration of September’s losses in just two incidents — accounting for roughly 92% of the month’s total — highlights a pattern that has defined much of 2026’s security landscape: rather than losses being spread evenly across many small exploits, a small number of large, sophisticated attacks against centralized exchanges and major infrastructure providers have driven the overwhelming majority of total crypto losses for the year.
How Users Can Protect Their Funds
Given the scale and frequency of exchange and protocol breaches in 2026, security researchers consistently recommend several practical steps for crypto holders. Keeping only the funds needed for active trading on any centralized exchange, rather than long-term holdings, limits exposure if that platform is breached. Using a hardware wallet for long-term storage keeps private keys offline and away from exchange-side vulnerabilities, though users should verify their specific device model isn’t affected by any known firmware issues, as was the case with Coldcard earlier this year.
Enabling withdrawal address whitelisting and two-factor authentication on every exchange account adds a layer of friction against unauthorized transfers. Users should also remain skeptical of unsolicited contact referencing account activity, firmware updates, or “support” requests for seed phrases or private keys, since legitimate companies never request this information directly. Finally, diversifying holdings across multiple reputable platforms and storage methods, rather than concentrating all assets in a single exchange or wallet, reduces the potential impact of any single point of failure.
What Comes Next
With September now standing as the costliest month of 2026 for crypto security incidents, attention will likely turn to whether exchanges and infrastructure providers respond with meaningfully strengthened third-party vendor vetting and internal authorization controls — the specific weaknesses exploited in the Bitget incident. For now, the month serves as a stark reminder that even well-established, large-scale platforms remain vulnerable to sophisticated attacks, and that fund security ultimately depends on a combination of platform-level safeguards and individual user practices working together.