September was officially crypto's worst hack month of 2026: 55 major incidents and $766M stolen, according to PeckShield. That's up ~462% from August's $136.3M. CertiK puts the year-to-date total at 656 incidents and about $2.68B.
Now look at how concentrated it is. Two incidents, the Bitget hot-wallet breach ($387.5M, Sept 24) and the Liquid Network exploit (~$320M, Sept 6), make up 92% of the month's losses. The other 53 hacks combined account for roughly $60M (my math).
And the headline number overstates what's actually gone. The Liquid attacker returned about $285M, roughly 85% of what was taken. Net of the funds returned so far, September's real loss is closer to $470M (my math). Still terrible. Just not the number in the headlines.
Both big hits also came through doors audits don't cover. Bitget was breached via compromised third-party security software. Liquid's flaw was a validation bug in the Elements codebase that let an attacker mint about 4,000 unbacked L-BTC. Neither was a classic smart-contract bug.
So which story is true: an industry getting hacked more often, or an industry with a couple of catastrophic single points of failure?
#CryptoSecurity #PeckShield
Now look at how concentrated it is. Two incidents, the Bitget hot-wallet breach ($387.5M, Sept 24) and the Liquid Network exploit (~$320M, Sept 6), make up 92% of the month's losses. The other 53 hacks combined account for roughly $60M (my math).
And the headline number overstates what's actually gone. The Liquid attacker returned about $285M, roughly 85% of what was taken. Net of the funds returned so far, September's real loss is closer to $470M (my math). Still terrible. Just not the number in the headlines.
Both big hits also came through doors audits don't cover. Bitget was breached via compromised third-party security software. Liquid's flaw was a validation bug in the Elements codebase that let an attacker mint about 4,000 unbacked L-BTC. Neither was a classic smart-contract bug.
So which story is true: an industry getting hacked more often, or an industry with a couple of catastrophic single points of failure?
#CryptoSecurity #PeckShield
