In September 2026, crypto hacks and exploits led to losses of over $766 million, making it the worst month of the year for crypto security, according to CertiK. Two major incidents made up more than 92% of these losses: the $387.5 million Bitget hack and the $318.7 million Liquid Network exploit. CertiK recorded total losses of $766.45 million, while more than $270 million was classified as returned or frozen.
#PeckShieldAlert In Sep. 2026, the crypto industry experienced 55 major hacks, resulting in total losses of $766.49M – a ~462% month-over-month increase from August’s $136.3M.
The #Bitget incident (~$387M) and #LiquidNetwork (~$320M, with $285M returned) have jumped to #1 & #2… pic.twitter.com/abePPGX7Y5
— PeckShieldAlert (@PeckShieldAlert) October 1, 2026
CertiK’s figures show how sharply crypto security losses increased during September. The month’s total was around 3.5 times the $215 million recorded in August.
The Bitget attack was the largest incident of the month. About $387.5 million was stolen from the cryptocurrency exchange’s hot wallets on Sept. 24. The company said its cold wallets and separate Bitget Wallet product were not affected and that its private keys were not stolen.
The second-largest incident involved the Liquid Network, a Bitcoin sidechain operated by Blockstream. The exploit resulted in about $318.7 million worth of unbacked Liquid Bitcoin, or L-BTC, being issued.
Together, the Bitget and Liquid incidents accounted for more than 92% of September’s total losses. CertiK classified around $270.6 million of the monthly figure as returned or frozen.
The Bitget attack was linked to a third-party security product. According to interim findings from blockchain security firm SlowMist and Google Cloud’s Mandiant, malicious activity had been taking place since Aug. 31. The attacker allegedly exploited a zero-day vulnerability in a third-party security product, gained high-level internal credentials and later moved to a production wallet server.
Mandiant said the attacker used a custom withdrawal tool based on Bitget’s own withdrawal logic. The attackers eventually transferred assets across several blockchains, including Ethereum, XRP Ledger, TRON, BNB Chain, Base, Arbitrum, Optimism and Avalanche.
Bitget has said its User Protection Fund would absorb the financial impact. The exchange reported that the fund had been restored to $309 million by Sept. 30.
The Liquid Network exploit had a different technical cause. According to Liquid’s incident report, a vulnerability in how nodes cached range-proof verifications allowed an invalid transaction to pass validation. This resulted in L-BTC being created without sufficient Bitcoin backing.
Around 3,400 BTC was later returned by the attacker, who described themselves as a white-hat hacker. About 600 BTC remained outstanding as of Sept. 30.
Other incidents in CertiK’s September tally included attacks involving Safe Wallet users, D’CENT, Duelbits, Astroport and Nostra Finance. The Safe Wallet-related incident resulted in around $7.8 million in losses, while D’CENT was listed at $6.03 million and Duelbits at $5.97 million.
The types of attacks also provide an important part of the September picture. CertiK listed third-party services as responsible for $387.5 million in losses, while invalid signatures accounted for $324.7 million. Wallet compromises contributed about $20.1 million, followed by improper permission controls at $13.3 million and reentrancy attacks at about $2.25 million.
The figures show that September’s damage did not mainly come from traditional smart-contract vulnerabilities. Instead, third-party infrastructure, signature and validation problems, wallet compromises and permission issues accounted for much of the reported losses.
CertiK’s first-half 2026 report had already recorded more than $1.31 billion in losses across 344 incidents between January and June. September’s figures add another major security setback to an already costly year for the crypto industry.

Source: certik.com
However, the $766 million figure should not be interpreted as permanent customer losses in every case. Some stolen or affected assets were recovered or frozen. The Liquid attacker returned a large portion of the funds, while Bitget said it would use its protection fund to cover customer losses.
Several questions also remained unresolved at the end of September, including the identity of the third-party security products involved in the Bitget attack and the attribution of the attack. The incidents underline the growing importance of security beyond smart contracts, particularly when crypto platforms depend on external infrastructure and complex transaction systems.
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like










Leave a comment