A costly bloodbath for crypto security

September 2026 goes down in history as one of the most expensive months for security breaches in the crypto industry. According to figures from security analysts PeckShield and CertiK, between $766 and $768 million was stolen from platforms and protocols throughout the month, writes CryptoPotato (cryptopotato.com).

That marks a sharp increase from August, when losses stood at $136.3 million according to PeckShield – and even more pronounced when looking at CertiK's figures, which show an increase of as much as 248 percent month-over-month.

However, the picture is more nuanced than the numbers first suggest. Two individual incidents – the breach at exchange Bitget and the exploit of Blockstream's Liquid Network – accounted for approximately 92 percent of the entire month's losses. Stripping away these two cases, the remaining 53 hacks in September totaled around $59 million, less than half of August's total losses.

766
million dollars total loss in September
92%
share from Bitget and Liquid
59
million dollars from the remaining 53 hacks
Crypto hackers stole $766 million in September – worst in two years - Bilde 1

Bitget: Spoofing of backend systems

The most widely covered single incident was the breach at exchange Bitget on September 24 at 18:31 UTC. The loss was initially estimated at $351.6 million, but following further chain analysis the amount was revised upward to $387.5 million.

According to security firm SlowMist, the attacker began reconnaissance as early as late August. The attack targeted a backend system within the exchange's wallet infrastructure, where the attacker forged transaction data and tricked the authorization process into releasing funds – without directly compromising private keys.

Bitget CEO Gracy Chen stated that cold storage, master keys, and the standalone Bitget Wallet app were not affected. The exchange used its user protection fund, which before the incident contained over $464 million, to cover the loss without reducing customer balances. The fund was later replenished to $309 million, including 3,705 bitcoin, on September 30.

We will not run from this, and every dollar will be accounted for

In the aftermath of the incident, Chen pointed to possible North Korean state involvement, without ruling out internal complicity. This attribution has not yet been independently confirmed by a third party, and should be read with caution.

Crypto hackers stole $766 million in September – worst in two years - Bilde 2

Liquid Network: Fake bitcoin via consensus flaw

The second major incident hit Blockstream's sidechain Liquid Network as early as September 6. A flaw in the validation logic of the Elements software, which runs the sidechain, made it possible to create an unrealistic 3,998.5 L-BTC – cryptocurrency with no real backing in reserves.

The fake tokens were then redeemed through SideSwap's bridge for payout, which drained Liquid's bitcoin reserves from 4,205 down to just 197 BTC. The multisignature keys controlled by the federation governing the network were not compromised – the weakness lay in the protocol code itself.

In a surprising turn of events, the attacker returned as early as the following day, September 7, returning 3,400 of the stolen bitcoins – worth between $270 and $285 million – to the reserves. Around 600 bitcoin, however, remained unrecovered.

Several smaller incidents in the shadows

Beyond the two major cases, security firms registered a number of smaller breaches throughout September, including:

  • Safe Wallet: around $7.8 million
  • Crypto casino Duelbits: $5.9–7 million
  • Hardware wallet provider DCENT: around $6 million
  • The Nostra oracle: around $3.5 million

CertiK breaks down September's attack vectors as follows: protocol and smart contract exploits accounted for a full 95.5 percent of losses (approximately $733.8 million), while private key compromises, wallet breaches, and phishing made up the remaining shares, with significantly lower volume than previous quarters.

Two incidents explain almost everything – the rest of the industry had a relatively normal month

Source criticism: The numbers vary

It's worth noting that different security firms operate with somewhat divergent figures. CertiK estimates gross losses at between $768.4 and $768.5 million spread across 97–98 incidents, while PeckShield lands on $766.49 million across 55 major incidents. Both sources are recognized players in on-chain analysis, but methodological differences in how incidents are counted and valued explain the discrepancies. Net losses, after funds were frozen or returned, are estimated by CertiK at around $495.3 million.

The cumulative figures for 2026 so far are also concerning: CertiK reports 656 incidents with combined damage of $2.68 billion, which already exceeds total losses for the entire preceding year.

What it means for users and the industry

Immunefi founder Mitchell Amador points to a pattern where centralized exchanges (CeFi) experience fewer but far more severe incidents than decentralized protocols (DeFi), often linked to weaknesses in key management – an area that rarely undergoes the same type of security audit as smart contracts.

For Norwegian and Nordic investors using international exchanges like Bitget, the incident underscores the importance of user protection funds and how quickly an exchange can absorb losses without affecting customer balances. The fact that Bitget managed to cover the entire breach without a haircut to users sets it apart from several previous exchange collapses where customer funds have been permanently lost.

At the same time, the Liquid case illustrates an increasingly complex security risk: even protocols without compromised keys can be hit hard by flaws in underlying consensus and validation logic.