Crypto Security Losses Surpass $1.26 Billion in Q3, Bitget Hack Accounts for Nearly One-Third

Crypto attacks and security incidents caused approximately $1.26 billion in losses during Q3 2026, up 53.9% from $819.4 million in Q2, according to data from blockchain security firm CertiK. The number of incidents also increased from 219 to 247.

September alone recorded roughly $769 million in losses across 99 incidents, with exploits accounting for nearly 96% of the total. After approximately $273 million was frozen or recovered, adjusted losses stood at around $495.3 million.

The $387.5 million Bitget hack was the largest incident of the quarter, accounting for roughly 31% of total losses. The attacker moved assets from several hot wallets to addresses under their control. Bitget said the incident was linked to a vulnerability in a third-party security product that allowed the attacker to obtain high-level internal credentials and forge withdrawal instructions.

Notably, an investigation by SlowMist found that malicious activity related to the Bitget incident may have begun as early as August 31, weeks before the funds were transferred from the hot wallets on September 24.

Other major Q3 incidents included the $319 million Liquid Network breach, a $120 million Tectonic exploit, and the $112.7 million Coldcard theft.

The figures highlight the continued security risks facing the crypto industry, with attackers increasingly targeting infrastructure, internal access controls and third-party systems, rather than relying solely on direct smart-contract exploits.