In September, crypto hacks set a new monthly record for 2026, following the Bitget exploit. The amount of hacked funds rose by 462% in September compared to August. 

A total of $766.49M was stolen in various hacks in September, of which $387.5M came from the Bitget hack. The past month was also the peak of Q3 hacks. The last month also surpassed the total from April, when the KelpDAO hack boosted overall losses to over $648M. 

In September, hacks varied by their target and technique. The Liquid Network exploit took away $320M, of which around $285M was returned. Bitget and Liquid Network are now the number 1 and number 2 hacks for 2026, surpassing the previous exploits of Drift Protocol, KelpDAO, and LayerZero. 

September ended with two of the year’s biggest crypto hacks A total of 99 larger hacks happened in September, though the bulk of thefts affected only Bitget and Liquid Network. September was the worst month for crypto hacks in 2026 to date. | Source: DeFi Llama

Another notable exploit was the attack against a Gnosis safe, which was front-run by the Yoink bot and the funds were returned. Other hacks ranged between $3M and $7M, targeting wallets, bridges, or other Web3 apps, based on data from PeckShield.

In total, September’s hacks had 13 exploits for over $500K, though the main proceeds skewed to the biggest exploits. 

Following the hacks, the funds are moved within hours, later mixed within days through DEX swaps, the Tornado Cash mixer, and no-KYC exchanges. In September, activity also showed up in swapping funds for Monero (XMR) and shielded ZCash (ZEC), showing an attempt to deepen privacy.

Crypto hacks use varied approaches

The biggest crypto exploits were due to compromised wallet keys, giving hackers access to Bitget hot wallets. However, hacks were extremely varied in the past month, with a large share exploiting Web3 infrastructure. 

Flaws in bridge, contract and minting logic were still exploited, possibly with the help of AI. Decentralized price manipulation and trading exploits were also a source of minor losses. 

Overall, hacks remained at an elevated baseline in the past two years. Usually, more active hacks coincide with a bull market. The last two years of hacks showed that attacks happen regardless of crypto sentiment. 

The main goal of hacks was to access points of elevated liquidity. As Web3 usage evolved, there were enough protocol targets to drain either through social engineering or logic exploits.

Crypto hacks raised their general incidence in September

Certik data showed that crypto hacks not only increased their overall haul, but the number of incidents increased. Certik analysts counted 99 security incidents for the past month. 

Total losses in Q3 reached $1.2B, up 53% from Q2, where hackers stole $819.4M. For the whole quarter, incidents jumped by 12.8%, to a total of 247 exploits. 

For crypto natives, scams were virtually not a threat, making up only 1% of all exploits. Phishing was still a strong attack vector, taking over 11% of incidents for Q3. The breakdown of incidents shows the flaw requires even stricter security and audits on the side of protocols, exchanges and other ecosystem participants.

The most attacked chains were still Ethereum and BNB Smart Chain, with the occasional attack on niche L2 networks like Liquid. 

Certik also noted one big shift in 2026 compared to previous years. More attacks are targeting private persons in Europe, with 39 incidents in H1 2026, compared to just 14 incidents in 2025. While attacks against crypto owners are extremely rare in other regions, Europe leads the counts for the ‘wrench attack’ statistic, as crypto owners are exposed due to reporting requirements.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.