Bitcoin is up 40 this season, and hackers also set a record: $1.26 billion drained in three months 💥
📈 进群一起分析行情
According to the latest statistics from blockchain security firm CertiK, in Q3 2026 there were a total of 247 security incidents in the crypto industry, with losses totaling $1.26 billion. September was the worst—99 incidents in a single month, the most since February 2025; the stolen amount was $768.5 million, setting the highest monthly figure for 2026. Extending the timeline, cumulative losses since the start of this year have already reached $2.68 billion.
The biggest single incident came from a vulnerability in an exchange, worth roughly $387 million—one case accounted for about a third of the quarter’s total losses 🦖
The contrast is right here. In the same quarter, Bitcoin rose by about 40%, spot ETFs pulled in tens of billions of dollars, and analysts’ wording was “a new bull market is here.” Money keeps pouring in—but the amount being scooped up is also setting fresh records at the same time.
Why weren’t institutions hit much this time? Senior analyst Nicolai Sondergaard at Nansen puts it plainly: most institutions buy regulated, standardized products that they can understand (ETFs, custody), and they don’t touch on-chain DeFi. In other words, most of the stolen funds happened on the side of retail users and on-chain protocols.
Even more worrying is insurance. A report from CoinGecko at the end of August showed on-chain crypto insurance underwriting capacity was only $130.2 million, down 20.2% from $163 million a year earlier—risk is rising, but the safety net is shrinking ⚠️ Sondergaard’s view is that reputational damage may be even bigger than the losses themselves. Repeated vulnerabilities could make institutions slow down, prompt regulators to get stricter, and push asset allocators to demand higher risk premiums.
Another new variable is AI. Security firm Blockaid expects multiple incidents involving AI agents. The most common technique is “prompt injection”—using hidden instructions to trick an AI agent into doing the attacker’s work. Finding vulnerabilities is shifting from “skilled engineers spending months” to “machines running by the hour.”
My take: the shortcoming of this bull run that’s being most underestimated isn’t regulation—it’s security. There’s another side to a bull market too: the economic incentives for attacks get stronger. As long as someone is willing to pay for stolen assets, vulnerabilities will be exploited again and again. For people who self-custody, what matters most isn’t chasing hotspots—it’s managing three things properly: permissions, private keys, and phishing.
Do you keep more of your assets on exchanges, or do you hold them in your own wallet? Let’s talk in the comments.
Click the avatar to watch the live stream
Every day, I’ll help you track crypto headlines—not just what happens in the news, but also the logic and opportunities behind it 👀🚀
📈 进群一起分析行情
According to the latest statistics from blockchain security firm CertiK, in Q3 2026 there were a total of 247 security incidents in the crypto industry, with losses totaling $1.26 billion. September was the worst—99 incidents in a single month, the most since February 2025; the stolen amount was $768.5 million, setting the highest monthly figure for 2026. Extending the timeline, cumulative losses since the start of this year have already reached $2.68 billion.
The biggest single incident came from a vulnerability in an exchange, worth roughly $387 million—one case accounted for about a third of the quarter’s total losses 🦖
The contrast is right here. In the same quarter, Bitcoin rose by about 40%, spot ETFs pulled in tens of billions of dollars, and analysts’ wording was “a new bull market is here.” Money keeps pouring in—but the amount being scooped up is also setting fresh records at the same time.
Why weren’t institutions hit much this time? Senior analyst Nicolai Sondergaard at Nansen puts it plainly: most institutions buy regulated, standardized products that they can understand (ETFs, custody), and they don’t touch on-chain DeFi. In other words, most of the stolen funds happened on the side of retail users and on-chain protocols.
Even more worrying is insurance. A report from CoinGecko at the end of August showed on-chain crypto insurance underwriting capacity was only $130.2 million, down 20.2% from $163 million a year earlier—risk is rising, but the safety net is shrinking ⚠️ Sondergaard’s view is that reputational damage may be even bigger than the losses themselves. Repeated vulnerabilities could make institutions slow down, prompt regulators to get stricter, and push asset allocators to demand higher risk premiums.
Another new variable is AI. Security firm Blockaid expects multiple incidents involving AI agents. The most common technique is “prompt injection”—using hidden instructions to trick an AI agent into doing the attacker’s work. Finding vulnerabilities is shifting from “skilled engineers spending months” to “machines running by the hour.”
My take: the shortcoming of this bull run that’s being most underestimated isn’t regulation—it’s security. There’s another side to a bull market too: the economic incentives for attacks get stronger. As long as someone is willing to pay for stolen assets, vulnerabilities will be exploited again and again. For people who self-custody, what matters most isn’t chasing hotspots—it’s managing three things properly: permissions, private keys, and phishing.
Do you keep more of your assets on exchanges, or do you hold them in your own wallet? Let’s talk in the comments.
Click the avatar to watch the live stream
Every day, I’ll help you track crypto headlines—not just what happens in the news, but also the logic and opportunities behind it 👀🚀
