In September 2026, losses caused by crypto hacker attacks exceeded $766 million, making it the month with the most severe theft of digital assets so far this year. Two independent blockchain security companies tracked these losses, and although they counted different numbers of incidents, their estimated losses were very close, indicating that the scale of vulnerability incidents that month was enormous and could not be ignored.
Key Points
- September 2026 was the month with the most severe losses due to crypto hackers and vulnerability exploits this year, with losses exceeding 766 million US dollars.
- PeckShield reported 55 major incidents, resulting in a total loss of 766.5 million US dollars; CertiK recorded 97 incidents, with a loss of 768.4 million US dollars.
- Most of the losses in September came from two incidents: Bitget suffered a hack resulting in a loss of $388 million, and Liquid Network was attacked, resulting in a loss of $320 million.
- It is reported that more than $270 million stolen in the Liquid Network attack has ultimately been recovered.
- According to the 2026 dashboard of CertiK, there have been 656 security incidents so far this year, resulting in a cumulative loss of 2.68 billion US dollars.
September 2026 became the worst month for crypto hackers
According to two organizations that track this field, the total losses in September increased significantly compared to August. PeckShield reported that there were 55 major incidents that month, with a total theft amount of 766.5 million US dollars. Meanwhile, CertiK recorded even more incidents, a total of 97, and estimated the losses for that month at 768.4 million US dollars.
The difference between these two figures is less than 2 million US dollars, which is particularly noteworthy considering that the two companies use different statistical methods and track different ranges of events. Such overlap also confirms the scale of losses in September: it was not a single catastrophic vulnerability that distorted the data, but rather the entire crypto ecosystem was frequently attacked over a month.
In a statement released on Wednesday, CertiK stated that this change "clearly reminds us how quickly the threat environment can change."
Bitget and Liquid Network dominated the losses for that month.

The two attacks in September far exceeded other incidents. The Bitget hacker incident resulted in a loss of $388 million, while an independent vulnerability exploit on Liquid Network led to the theft of $320 million. Together, these two incidents amounted to approximately $708 million, accounting for the vast majority of the total losses for that month.
Bitget Vulnerability Suspected to Be Related to North Korea
According to CEO Gracy Chen, on the afternoon of September 24th, Bitget discovered 19 unauthorized transfers originating from certain areas of its hot wallet and warm wallet systems, while the cold wallet was not affected. CNBC cited Chen as stating that investigators traced the Internet Protocol addresses to a VPN service previously associated with North Korean hacker groups, and the characteristics of this attack match past patterns of activities related to that country.
Chen indicates that the security team at Bitget discovered that attackers had infiltrated a critical backend wallet system, utilized this system to forge transfer data, and triggered the exchange's authorization signature process. However, a private key leak has been ruled out. Bitget states that all losses will be covered by their user protection fund, which has a size of over 464 million US dollars.
Liquid Network Part of the funds has been recovered.
The scale of losses incurred in the attack on Liquid Network ranks second only to that of Bitget, amounting to 320 million US dollars. Unlike the Bitget incident, according to reports cited by Cointelegraph, a considerable portion of the funds stolen from Liquid Network—over 270 million US dollars—was later returned. So far this year, both incidents have been among the largest crypto theft cases, and the partial recovery of funds in the Liquid Network case has become one of the few bright spots in this costly month.
Smaller events and the overall situation in 2026
Not every vulnerability in September was as prominent as Bitget or Liquid Network, but some smaller platforms also suffered substantial losses. Safe Wallet lost 7.8 million dollars, DCENT lost 6 million dollars, and Duelbits lost 5.9 million dollars. These three incidents added up to a total loss of 19.7 million dollars for that month. Compared to the two major attacks, this is just a small portion, but it still reminds people that smaller crypto platforms are still exposed to risks.
From an annual perspective, the losses in September are even more prominent. The security dashboard of CertiK shows that as of now in 2026, there have been a total of 656 security incidents, resulting in cumulative losses of 2.68 billion US dollars. The losses in September alone account for more than 25% of the annual total, although 97 incidents that month represent only about 15% of the total number of incidents recorded by CertiK this year.
Constantly changing threat environment
CertiK's statement for the month summarizes the broader concerns of the industry. In addition to the phrase 'how quickly the environment can change under threat,' the company's data also shows that in September, the cumulative losses for 2026 were pushed up to 2.68 billion US dollars, and this figure continues to rise as the years progress.
For exchanges and wallet service providers, the data from September highlights a persistent issue: backend wallet systems and third-party integrations remain the main targets of attacks. As suspected in the Bitget case, attackers involved in complex operations continue to test the infrastructure that platforms once considered secure. For users and investors, this month serves as a reminder that even platforms with substantial funds and dedicated protection funds are not immune to attacks; however, the Bitget case also shows that such insurance-like reserves can at least mitigate some of the losses for customers when vulnerabilities do occur.
This article was generated with the assistance of artificial intelligence and has been reviewed by an editorial team.












