September 2026 set an unwelcome record for cryptocurrency security, with independent trackers PeckShield and CertiK both estimating more than $766 million in losses, making it the worst month of the year. PeckShield counted 55 major incidents totaling $766.49 million, while CertiK counted 97 incidents and $768.4 million, a roughly 462% increase from August’s $136.3 million. For the third quarter, CertiK recorded $1.2 billion in losses across 247 incidents, up 53% from Q2; year-to-date losses reached $2.68 billion across 656 security incidents.
The largest single event was the September 24 breach at Bitget. The exchange initially reported $351.6 million but later confirmed about $387.5 million reached attacker-controlled addresses after investigators expanded the estimate. Mandiant and SlowMist found that compromised third-party security software allowed unauthorized access to portions of Bitget’s hot and warm wallet infrastructure across Ethereum and other EVM networks, XRP Ledger, Zcash and Tron. Affected assets included ETH, XRP, USDT, USDC, ZEC, BNB, AVAX and TRX. Bitget said cold wallets and private keys were not compromised, fixed the flaw, restored BTC, ETH and USDT withdrawals, and replenished its Protection Fund above $300 million. Circle and Tether froze about $318,000 in stablecoins linked to the attack, and Bitget offered a 5% bounty for asset freezing or recovery.
Liquid Network suffered the second-largest incident on September 6. A vulnerability in the Elements codebase’s rangeproof verification cache allowed an attacker to create roughly 4,000 unbacked L-BTC and then withdraw close to 4,000 real BTC, reducing the federation’s Bitcoin reserve from about 4,205 BTC to 197 BTC. CertiK valued the affected amount at 3,998.5 L-BTC, or around $318.7 million. In an unusually positive outcome, the attacker returned 3,400 BTC on September 7 after onchain negotiations, leaving about 602 BTC outstanding. Blockstream halted the network, released Elements v23.3.4 with a hardened proof-cache implementation, and block production resumed on September 9, though peg-outs remained suspended as of late September.
Smaller September incidents included a Safe Wallet loss estimated at $7.8 million, DCENT at around $6 million, and Duelbits at about $5.9 million. CertiK said Ethereum and BNB Smart Chain remained the most attacked chains, with occasional exploits on niche L2 networks like Liquid. Stolen funds were being moved within hours and mixed through DEX swaps, Tornado Cash, no-KYC exchanges, Monero and shielded Zcash, complicating recovery efforts.