Hackers stole about $768.4 million in cryptocurrency during September, making it the costliest month for crypto security incidents in 2026.
Key Points:
- CertiK counted 97 incidents with estimated losses of $768.4 million, while PeckShield tracked 55 incidents totaling $766.5 million.
- Bitget and Liquid Network accounted for roughly 92% of the losses in PeckShield’s September tally.
- CertiK’s year-to-date data showed 656 security incidents and about $2.68 billion in losses through September.
Bitget Crypto Losses
September produced the highest monthly crypto loss total of 2026, although the firms recorded different incident counts.
Bitget was the largest single case, with its loss estimate rising from an initial $351.6 million to $387.5 million after investigators confirmed how much cryptocurrency reached attacker-controlled addresses. The exchange’s breach accounted for roughly half of CertiK’s monthly total.
Liquid Network’s Sep. 6 exploit involved a different failure, as a verification flaw allowed an attacker to create around 4,000 Liquid Bitcoin (L-BTC) without corresponding Bitcoin (BTC) backing. The attacker then used the network’s withdrawal process to extract close to 4,000 BTC, cutting its Bitcoin reserve from roughly 4,205 BTC to 197 BTC.
CertiK valued 3,998.5 L-BTC at about $318.7 million when the attack occurred. Most of those assets were later returned, with reports saying more than $270 million came back and 3,400 BTC was restored to the network.
Also Read: Can Bitcoin Hit $113,000? Citigroup Thinks ETF Inflows Will Get It There
CertiK Security Findings
SlowMist, which investigated the Bitget breach, said activity linked to the attack began weeks before the theft, but it did not publicly identify a suspect. Bitget CEO Gracy Chen said the exchange suspected North Korean hackers may have been involved.
Bitget later restored withdrawals for Bitcoin, Ethereum (ETH) and Tether (USDT), while reporting a 131% reserve ratio across 19 covered assets and more than $300 million in its Protection Fund. The exchange said full operations were resuming gradually.
Smaller September incidents also added to the total, including losses of about $7.8 million at Safe Wallet, $6 million at DCENT and $5.9 million at Duelbits. CertiK also cited a $7.81 million MEV-related theft that was later returned and a $3.5 million exploit affecting Nostra’s oracle.
By the end of September, CertiK’s 2026 tally had reached about 656 security incidents and approximately $2.68 billion in losses, showing how two unusually large breaches pushed one month sharply above the rest of the year.
Read Next: OpenAI Says A Moonshot-Linked Push Of 16,000 Requests Hunted Its Hidden Logic

