
Crypto hacks caused over $766 million in losses during September 2026, making it the worst month of the year for digital asset theft so far. Two separate blockchain security firms tracked the damage, and while their incident counts differed, both arrived at remarkably close loss estimates — a sign of just how large and unmistakable the month’s breaches were.
Key takeaways
September 2026 marked the costliest month this year for crypto hacks and exploits, with losses exceeding $766 million.
According to PeckShield, there were 55 significant incidents totaling $766.5 million, whereas CertiK documented 97 incidents amounting to $768.4 million.
Most of September’s losses stemmed from two events: the $388 million Bitget hack and the $320 million Liquid Network exploit.
Reports indicate that over $270 million taken in the Liquid Network exploit was eventually recovered.
According to CertiK’s 2026 dashboard, there have been 656 security incidents this year so far, resulting in $2.68 billion in total losses.
September 2026 Marks Worst Month for Crypto Hacks
September’s total marks a sharp jump from August, according to both firms tracking the sector. PeckShield counted 55 major incidents during the month and put the stolen total at $766.5 million. CertiK, meanwhile, recorded a higher number of incidents — 97 in all — and estimated the month’s losses at $768.4 million.
The two figures land less than $2 million apart, which is notable given that the firms use different counting methods and track different sets of incidents. That overlap lends weight to the scale of September’s losses: this wasn’t a single catastrophic breach skewing the numbers, but a month packed with activity across the crypto ecosystem.
Why this matters: when two independent trackers converge on nearly identical totals, it signals that the month’s crypto security incidents weren’t isolated anomalies but part of a broader pattern hitting multiple platforms at once. CertiK summed up the shift bluntly, saying in a statement published Wednesday that “September was a stark reminder of how quickly the threat landscape can shift.”
Bitget and Liquid Network Lead the Month’s Losses
Two attacks dwarfed everything else that happened in September. The Bitget hack accounted for $388 million in losses, while a separate exploit on the Liquid Network resulted in $320 million stolen. Combined, those two incidents made up roughly $708 million — the overwhelming majority of the month’s total.
North Korea suspected in Bitget breach
According to CEO Gracy Chen, Bitget identified 19 unauthorized transfers originating from portions of its hot and warm wallet systems during the afternoon of September 24, with cold wallets remaining unaffected. Per CNBC, Chen noted that investigators traced internet protocol addresses to VPN services previously associated with a North Korean hacking group, and that the attack’s characteristics matched patterns from prior operations linked to that nation.
According to Chen, Bitget’s security team found that an attacker had compromised a vital backend wallet system, exploited it to falsify transfer data, and activated the exchange’s authorization-signing process, though a private key breach was ruled out. According to Bitget, the full amount lost will be covered by its User Protection Fund, which contains more than $464 million.
Liquid Network’s partial recovery
The Liquid Network exploit came in just behind Bitget’s in size, with $320 million taken. In contrast to the Bitget incident, however, a substantial share of the funds taken in the Liquid Network exploit — over $270 million — was later returned, according to reports cited by Cointelegraph. Both incidents rank among the largest crypto thefts recorded so far this year, and the partial recovery on Liquid Network stands out as one of the rare bright spots in an otherwise costly month.
Smaller Incidents and the Bigger 2026 Picture
Not every September breach made headlines on the scale of Bitget or Liquid Network, but several smaller platforms still took real hits. Safe Wallet lost $7.8 million, DCENT lost $6 million, and Duelbits lost $5.9 million. Combined, those three incidents added $19.7 million to the month’s total — a relatively small slice next to the two headline attacks, but still a reminder that smaller crypto platforms remain exposed.
Zooming out to the full year puts September’s damage into sharper context. CertiK’s security dashboard shows 656 security incidents across 2026 so far, with cumulative losses of $2.68 billion. September’s losses alone represent more than 25% of that entire yearly total, even though the month’s 97 incidents make up only about 15% of all incidents CertiK has recorded this year.
That gap between incident share and loss share matters. It means September wasn’t simply a busy month for hackers — it was a month where a relatively small number of attacks did outsized financial damage, driven almost entirely by the Bitget and Liquid Network breaches.
A Shifting Threat Landscape
CertiK’s own framing of the month captures the broader concern for the industry. Beyond the statement about how fast the threat landscape can shift, the firm’s data shows September pushing the 2026 running total to $2.68 billion in losses — a figure that keeps climbing as the year progresses.
For exchanges and wallet providers, the September numbers underline a persistent problem: backend wallet systems and third-party integrations remain prime targets, and attackers tied to sophisticated operations — as suspected in Bitget’s case — continue to probe infrastructure that platforms assume is secure. For users and investors, the month serves as a reminder that even well-funded platforms with dedicated protection funds aren’t immune, though Bitget’s case shows that insurance-style reserves can at least limit the fallout for customers when a breach does happen.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
