Crypto hacks top $768M in September, worst month of 2026
September was the worst month of 2026 so far for crypto hacks, with two security firms estimating combined losses of roughly $766–$768 million across dozens of incidents. The largest single events were a $388 million breach at Bitget and a $320 million exploit of the Liquid Network, from which more than $270 million was later returned.

Why It Matters
The size and concentration of these losses underline a surge in successful attacks against crypto platforms and infrastructure, highlighting heightened risk for users and custodial services. The scale also contributes materially to the year-to-date security toll recorded by monitoring firms.
Key Facts
- Estimated losses (PeckShield): $766.5 million
- Estimated losses (CertiK): $768.4 million
- PeckShield incident count in September: 55 major incidents
- CertiK incident count in September: 97 incidents
- Largest incidents: $388M Bitget breach; $320M Liquid Network exploit (>$270M later returned)
Security monitors reported a sharp jump in crypto thefts in September, with two blockchain security firms producing near-identical tallies of damage. PeckShield logged 55 major incidents for the month and put the total stolen at about $766.5 million, while CertiK counted 97 incidents and estimated losses at roughly $768.4 million. Both firms noted the September totals were a sizable increase compared with August. The most costly events were a $388 million breach of the Bitget platform and a $320 million exploit of the Liquid Network. Reports indicate more than $270 million connected to the Liquid incident was subsequently returned. Those two cases alone accounted for the bulk of the monthly losses and rank among the year’s largest single thefts. Smaller but still material attacks also occurred in September. CertiK and other trackers identified losses at Safe Wallet ($7.8 million), DCENT ($6 million), and Duelbits ($5.9 million), among others. The diversity of affected targets — from exchanges and wallets to other service providers — illustrates the broad set of vectors attackers have used. CertiK’s security dashboard shows a larger picture for 2026: 656 recorded security incidents year-to-date, with cumulative losses of about $2.68 billion. Independent firms such as SlowMist have also been active in attribution and post-incident analysis, with one SlowMist report linking activity around the Bitget incident to a zero-day exploit observed on Aug. 31.
Keep Reading

MetaMask exits Ethereum validators amid undisclosed security incident

Bitcoin think tank questions MSCI’s ‘invisible committee’ over Strategy, Metaplanet rule

Bitcoin ETFs draw $6.3B in Q3 as BTC price rises nearly 43%
