September 2026 Becomes Worst Month for Crypto Hacks With $766M Stolen

1 hour ago 2 sources negative

Key takeaways:

  • September's $766M security losses signal structural crypto risk, pressuring exchange tokens and DeFi confidence.
  • Liquid Network's $318M exploit leaves 602 BTC outstanding, threatening L-BTC peg confidence near term.
  • Attackers' mixing via Tornado Cash, Monero, shielded Zcash lowers recovery odds, raising ZEC privacy scrutiny.

September 2026 set an unwelcome record for cryptocurrency security, with independent trackers PeckShield and CertiK both estimating more than $766 million in losses, making it the worst month of the year. PeckShield counted 55 major incidents totaling $766.49 million, while CertiK counted 97 incidents and $768.4 million, a roughly 462% increase from August’s $136.3 million. For the third quarter, CertiK recorded $1.2 billion in losses across 247 incidents, up 53% from Q2; year-to-date losses reached $2.68 billion across 656 security incidents.

The largest single event was the September 24 breach at Bitget. The exchange initially reported $351.6 million but later confirmed about $387.5 million reached attacker-controlled addresses after investigators expanded the estimate. Mandiant and SlowMist found that compromised third-party security software allowed unauthorized access to portions of Bitget’s hot and warm wallet infrastructure across Ethereum and other EVM networks, XRP Ledger, Zcash and Tron. Affected assets included ETH, XRP, USDT, USDC, ZEC, BNB, AVAX and TRX. Bitget said cold wallets and private keys were not compromised, fixed the flaw, restored BTC, ETH and USDT withdrawals, and replenished its Protection Fund above $300 million. Circle and Tether froze about $318,000 in stablecoins linked to the attack, and Bitget offered a 5% bounty for asset freezing or recovery.

Liquid Network suffered the second-largest incident on September 6. A vulnerability in the Elements codebase’s rangeproof verification cache allowed an attacker to create roughly 4,000 unbacked L-BTC and then withdraw close to 4,000 real BTC, reducing the federation’s Bitcoin reserve from about 4,205 BTC to 197 BTC. CertiK valued the affected amount at 3,998.5 L-BTC, or around $318.7 million. In an unusually positive outcome, the attacker returned 3,400 BTC on September 7 after onchain negotiations, leaving about 602 BTC outstanding. Blockstream halted the network, released Elements v23.3.4 with a hardened proof-cache implementation, and block production resumed on September 9, though peg-outs remained suspended as of late September.

Smaller September incidents included a Safe Wallet loss estimated at $7.8 million, DCENT at around $6 million, and Duelbits at about $5.9 million. CertiK said Ethereum and BNB Smart Chain remained the most attacked chains, with occasional exploits on niche L2 networks like Liquid. Stolen funds were being moved within hours and mixed through DEX swaps, Tornado Cash, no-KYC exchanges, Monero and shielded Zcash, complicating recovery efforts.

Previously on the topic:
Sep 29, 2026, 8:01 a.m.
NEAR Intents Blocks $50M in Stolen Funds Tied to $387.5M Bitget Hack
Sources
Crypto loses $768M in worst hack month of 2026
crypto.news 01.10.2026 10:09
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.