Crypto

Crypto Hacks in September 2026: Why $768 Million Was Stolen in the Worst Month of the Year

September 2026 was the worst month for crypto hacks all year — over $766 million stolen across dozens of incidents, per security firms PeckShield and CertiK. Here's what actually happened, why two breaches explain most of it, and what the pattern means for anyone holding crypto.

▶ View as web story

September 2026 was the worst month for crypto hacks of the entire year. Security firms PeckShield and CertiK both tracked more than $766 million stolen across dozens of incidents — a roughly 462% jump from August’s $136.3 million — and just two breaches, the Bitget hack and an exploit on Bitcoin’s Liquid Network, accounted for about 92% of the damage. Neither involved a stolen private key. Both came from exploiting how a system verified a transaction, not from stealing the keys that authorize one.

That distinction matters more than the headline number. Here’s what actually happened, incident by incident, and what the pattern says about where crypto security is actually breaking down in 2026.

How Bad Was September 2026, Exactly?

September saw the highest monthly crypto hack total of 2026, with two independent security firms landing on almost the same figure from different methodologies. PeckShield counted 55 major incidents totaling $766.5 million; CertiK counted 97 incidents (a broader net that includes more smaller exploits) at $768.4 million (Cointelegraph, Cryptonomist).

Metric August 2026 September 2026
Total losses ~$136.3 million ~$766.5–$768.4 million
Major incidents — 55 (PeckShield) / 97 (CertiK)
Change — ~462% increase month-over-month

For the quarter, CertiK logged 247 security incidents and $1.26 billion in total Q3 2026 losses, meaning September alone accounted for more than half of the entire quarter’s damage (CoinInsider).

The Two Hacks That Explain Almost Everything

Nearly all of September’s total comes down to two breaches with two very different failure modes.

Bitget — $387 million, September 24. Suspected North Korea-linked hackers didn’t steal a private key. They spoofed Bitget’s internal approval workflow to push through unauthorized withdrawals from hot and warm wallets across seven blockchain networks, while cold wallets stayed untouched. Bitget confirmed the loss and committed to covering it fully from its Bitcoin-backed Protection Fund. We covered the full mechanics in our Bitget hack explainer.

Liquid Network — $320 million, September 6. This one is the more technically interesting failure. Liquid Network is a Bitcoin sidechain run by Blockstream, used mainly by exchanges and institutions for faster, more private BTC transfers. At 13:53 UTC on September 6, an attacker exploited a flaw in a rangeproof verification cache inside Elements — the Bitcoin Core fork Liquid runs on — that let a single transaction pass validation even though its output wasn’t actually backed by real Bitcoin. That minted roughly 4,000 unbacked L-BTC out of thin air. The attacker then moved those tokens out through Liquid’s normal peg-out process via a federation member holding a peg-out authorization key, converting fake L-BTC into real BTC (Chainalysis; technical writeups at CodeAnt and Cryptonomist).

The uncomfortable detail: a fix for that exact rangeproof cache bug had already been committed to the Elements code repository on September 1 — five days before the exploit — but no production node had deployed it yet. The attacker, who later framed themselves as a “white-hat,” returned about 3,400 of the 4,000 BTC (roughly 85%) after Blockstream shipped a patch, while keeping about 598 BTC (around $47 million) as a self-declared bounty.

The Smaller Hacks That Didn’t Make Headlines

Outside the two giants, September had a steady drip of mid-size breaches that rarely get their own news cycle but add up:

Incident Approx. loss What happened
Safe Wallet $7.8 million Security incident tracked by PeckShield/CertiK monthly reports
DCENT $6.0 million Security incident tracked by PeckShield/CertiK monthly reports
Duelbits (crypto casino) ~$7 million Hot wallets on Ethereum, BNB Chain, and Tron drained in a suspected private-key compromise, per blockchain security firm Scam Sniffer

Duelbits is the clearest “classic” hack of the bunch: on September 24, its hot wallets sent 836 ETH, about 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB to newly created attacker addresses within minutes, with most of it swapped into roughly 2,234 ETH (about $6 million) and consolidated into a single address (CoinDesk). Duelbits took its platform offline in response.

Software Bugs vs. Stolen Keys: Two Different Problems

It’s tempting to lump every crypto hack into one bucket — “they got hacked” — but September 2026 is a useful case study in how different the actual failure points are:

Failure type Example What actually broke
Approval-system spoofing Bitget ($387M) Internal withdrawal-approval logic was tricked into approving unauthorized transactions — no key was stolen
Code validation bug Liquid Network ($320M) A cryptographic verification cache had a flaw that let fake, unbacked value pass as real
Private key compromise Duelbits (~$7M) Hot wallet keys were directly compromised and used to sign real withdrawals

This matters for anyone trying to learn from these events. “Use a hardware wallet” or “don’t share your seed phrase” — the standard advice — would not have prevented either of September’s two biggest hacks. Those failures happened entirely inside exchange and protocol infrastructure, before an individual user’s wallet was ever involved. The Duelbits-style hack is the one individual security hygiene can’t fix either, since it was the platform’s hot wallet keys, not a user’s, that were compromised.

Why September Was So Much Worse Than August

Three things compounded at once. First, two unusually large, unrelated incidents landed in the same month — Bitget and Liquid Network together were roughly $707 million of the ~$766 million total, meaning September’s “average” month would have looked fairly ordinary without them. Second, CertiK’s wider net (97 incidents vs. PeckShield’s 55) shows a genuine increase in smaller-scale exploits too, not just a statistical fluke from two big headlines. Third, Q3 2026 overall was already trending up — $1.26 billion in quarterly losses — suggesting September capped off a quarter where both attackers and defenders were more active, not an isolated spike.

None of this means crypto security got structurally worse overnight. It means two specific, preventable failures (a spoofable approval workflow, and a known bug that sat unpatched in production for five days) happened to land in the same four-week window.

What This Means If You Hold Crypto

This is not financial advice, and none of the incidents above change the investment case for any specific coin — but they’re a useful checklist for custodial risk:

  • Know who actually holds the keys. If your crypto sits on an exchange or inside a staking/custody product, you’re trusting that platform’s internal controls, not just cryptography. Our MetaMask/Lido staking incident explainer covers a related case where the distinction between “signing keys” and “withdrawal keys” mattered a lot.
  • A platform’s size doesn’t guarantee its internal process is airtight. Bitget is a major exchange; its hack came from process logic, not amateur mistakes.
  • “Returned funds” isn’t the same as “no harm done.” Liquid Network got back 85% of what was stolen, but that recovery depended on the attacker’s choice to return it, not on any security control working as intended.
  • Smaller platforms carry real, uninsured risk. Duelbits, Safe Wallet, and DCENT losses were a fraction of Bitget’s, but for anyone with funds on those specific platforms, the loss was total.

As always with crypto, do your own research on any platform’s security history, audit record, and insurance or reimbursement policy before leaving meaningful funds on it — and treat regulatory and tax treatment of any reimbursed or recovered funds as something to check with a professional, since it varies by jurisdiction.