BTC—ETH—SOL—XRP—BNB—ADA—DOGE—TRX—LINK—AVAX—DOT—LTC—
Live

Crypto hack losses hit $768 million in September, worst of 2026

Blockchain security firms PeckShield and CertiK put September crypto theft between about $766 million and $768 million, the heaviest month of 2026. A single breach at the exchange Bitget drove most of it.

By Yash Malviya

Published · 4 min read

Crypto thieves had their best month of the year in September. Two blockchain security firms, PeckShield and CertiK, put total losses between $766 million and $768 million, the heaviest monthly toll of 2026. One exchange breach caused most of it.

Both firms published their tallies on October 1. PeckShield counted 55 major incidents worth about $766.49 million. CertiK logged 97 incidents and a slightly higher figure of $768.4 million. The two track hacks in different ways, so their incident counts rarely line up. Their dollar totals landed less than $2 million apart.

What drove the September total

Almost half the money came from a single event. On September 24, attackers drained about $387.5 million from Bitget, one of the largest crypto exchanges by trading volume. The company said a backend system that helps approve withdrawals was compromised, letting the attackers push through transfers that should have been blocked. No ordinary private key theft, then. The funds left in a burst of transactions across several blockchains within hours.

Blockchain analytics firm Chainalysis attributed the Bitget theft to actors linked to North Korea. Investigators have not publicly tied the breach to any single named group. On its own, that one theft topped the crypto hacking bill for all of August. Bitget has since restored withdrawals for the assets involved.

The second big hit landed earlier, on September 6. An exploit on the Liquid Network, a Bitcoin sidechain, created roughly 4,000 L-BTC that had no matching Bitcoin behind it, a shortfall worth about $320 million at the time. Most of that came back. On September 7, about 3,400 BTC was returned.

Smaller thefts filled out the rest of the month. CertiK and PeckShield both logged dozens of lesser incidents, among them about $7.8 million taken from Safe Wallet, $6 million from the hardware wallet maker DCENT, and $5.9 million from the betting site Duelbits. None came close to the two headline breaches. Together they still ran into tens of millions.

Why the gross number overstates the damage

Not every stolen dollar stays stolen. CertiK said recoveries cut September's net losses to $495.3 million, about 35.6 percent below the gross figure. The Liquid Network return explains much of that gap. Even so, close to half a billion dollars went missing in thirty days and did not come back.

Neither firm said how much of the remaining total will ever be recovered. Victims of backend and bridge attacks often get little back once funds pass through mixers and cross-chain swaps. That is the hard part. For everyday holders, the repeated breaches are a reminder that coins left on an exchange sit under someone else's security, which is why many move long-term savings into cold storage.

A record quarter for crypto theft

September capped the worst three months of the year. The jump was steep. CertiK pegged third-quarter losses at $1.26 billion. Across 2026 so far, the firm has tracked 656 security incidents and about $2.68 billion in stolen value. It was also the busiest month for attacks since February 2025. September alone was more than five times August's $136.3 million. Bridges, backend systems and signing processes keep showing up as the weak points.

The damage goes beyond the balance sheet. Nicolai Sondergaard, a senior research analyst at Nansen, said the fallout can outlast the money lost. "Yes, it is bad optics," he said. "The reputational damage can still be larger than the losses themselves." Exchanges that lose customer funds tend to lose customer trust too, and trust is slower to rebuild than a hot wallet.

What to watch

October will show whether September was a spike or a trend. Watch three things. First, how much of the Bitget money investigators can freeze or claw back. Second, whether any group is formally named, since attribution often firms up weeks after a theft. Third, whether exchanges tighten the backend controls that failed here.

For now, the record stands. September 2026 is the costliest month for crypto theft the tracking firms have logged this year. Readers following the exploit beat can find more on our DeFi and protocols hub.

Frequently asked

How much did crypto hacks cost in September 2026?

Blockchain security firms put September 2026 losses between about $766 million and $768 million. PeckShield counted 55 major incidents worth $766.49 million. CertiK logged 97 incidents and $768.4 million. After funds returned by the Liquid Network and others, CertiK said the net loss fell to about $495 million.

What was the biggest crypto hack in September 2026?

The Bitget breach was the largest, with about $387.5 million drained on September 24. Attackers compromised a backend system that approved withdrawals rather than stealing a private key in the usual way. Chainalysis linked the theft to actors tied to North Korea, though no single group has been formally named.

Is 2026 a bad year for crypto security?

Yes, by the tracking firms' own count. CertiK recorded 656 security incidents and about $2.68 billion in losses across 2026 so far, with $1.26 billion of that in the third quarter alone. September was the worst single month, driven mainly by the Bitget and Liquid Network incidents.

Sources, and what is behind them

  1. Crypto lost $1.26 billion in hacks while bitcoin bulls enjoyed a monster quarter, CoinDesk (October 1, 2026)Press report
  2. Crypto loses $768M in worst hack month of 2026, crypto.news (October 1, 2026)Press report
  3. Crypto Hacks Top $768 Million in September, Worst Month of 2026, Blockonomi (October 1, 2026)Press report