Bitget’s $388M hack pushes Q3 crypto security losses past $1B

Crypto security losses topped $1.26 billion in Q3 2026, driven largely by a $387.5 million breach at Bitget. CertiK recorded 247 security incidents in the quarter, with September alone responsible for roughly $769 million in losses across 99 incidents.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 1 minute agoUpdated 1 minute ago0 views
Bitget’s $388M hack pushes Q3 crypto security losses past $1B

Why It Matters

The spike, led by a single large exchange hack and several multi-hundred-million-dollar exploits, signals growing systemic risk in crypto custody and smart-contract security and underscores the material financial impact of large breaches on quarterly industry loss totals.

Key Facts

  • Total Q3 security losses: $1.26 billion
  • Quarter-over-quarter change: Up 53.9% from $819.4 million in Q2 2026
  • Number of incidents in Q3: 247 (up from 219 in Q2)
  • Bitget loss: $387.5 million (about 31% of Q3 losses)
  • Largest other incidents: Liquid Network $319 million; Tectonic $120 million; Coldcard $112.7 million)

Crypto security incidents produced $1.26 billion in reported losses during the third quarter of 2026, according to data compiled by blockchain security firm CertiK. The total represents a 53.9% increase from the $819.4 million recorded in the prior quarter and was spread across 247 separate security events. The single largest contributor to Q3’s losses was the hack of exchange Bitget, which CertiK quantified at $387.5 million and estimated accounted for roughly 31% of the quarter’s total. Other major incidents included a $319 million exploit of Liquid Network on Sept. 6, a $120 million attack on Tectonic, and a $112.7 million theft involving Coldcard. September was an especially costly month, with CertiK reporting about $769 million in losses across 99 incidents. The firm said about $273 million of those funds were frozen or returned, producing adjusted losses of $495.3 million for the month. Exploits were the dominant loss type in September, responsible for about $734 million across 58 incidents — nearly 96% of that month’s reported losses. Bitget disclosed that it detected unauthorized transfers from several hot wallets on Sept. 24 and subsequently suspended withdrawals. The company attributed the breach to an attacker exploiting a vulnerability in a third-party security product to acquire internal credentials and submit forged withdrawal commands.

Keep Reading