Key Highlights:
- Crypto hack losses exceeded $768.5 million in September, up ~462% from the previous month of August and the largest month of 2026.
- Two massive exploits drove 92% of the total losses: Bitget ($387.5M) and Liquid Network ($318.7M).
- Net losses were reduced to $495.3 million with active mitigation and white-hat cooperation returning or freezing $273.2 million.
The cryptocurrency industry has just suffered its most devastating month of the year. According to the latest data compiled by blockchain security firms, crypto hack losses officially crossed the $768 million mark in September 2026. September is the month with the most significant number of digital asset exploits ever recorded, surpassing all previous months in 2026 and highlighting major flaws in centralized systems and scaling solutions.
According to Data released by PeckShield, there were 55 large-scale data breaches, with the amount of stolen funds reaching around $766.49 million. Meanwhile, CertiK’s Security Dashboard tracked a broader scope of 99 security incidents, reporting gross total losses of $768.5 million. Each case marks an astounding 462% year-over-year rise from a relatively quiet August, which saw a loss of $136.3 million, signaling the Web3 industry to pull back.
A Catastrophic Spike in 2026’s Threat Landscape
Prior to September, the highest loss recorded in a single month throughout 2026 occurred in April, when hackers made off with $646.89 million. The midsummer months of July and August had been giving a false sense of security, with totals in the $187 million to $214 million range.
September, however, turned this trend on its head with a very aggressive turn. The sudden growth is also a reminder of the fast-changing nature of the Web3 threat landscape, as per the blockchain security experts. These new data bring the total number of security incidents tracked on CertiK’s running dashboard to a troubling 656 in 2026, representing a cumulative loss of $2.68 billion.

Crypto Hack: The Two Megahacks Dominating the Charts
The amount of capital stolen from crypto hacks in September was not distributed evenly; rather, it was almost entirely through two historic, consecutive mega-exploits that accounted for about 92% of the capital stolen for the month.
1. Bitget Centralized Exchange Exploited (~$387.5M)
Bitget, a leading cryptocurrency exchange, experienced a significant security issue on its backend on September 24. The initial on-chain tracker estimates of damage totaled $351.6 million, but were later adjusted to $387.5 million. SlowMist’s investigation indicated that the threat actors took advantage of a third-party security product that was installed in Bitget’s system, which had a zero-day vulnerability. This vulnerability allowed them to create internal credentials that enabled them to create withdrawal instructions on Ethereum, Binance Smart Chain, Avalanche, and the XRP Ledger. According to Bitget CEO Gracy Chen, the losses would be fully covered by the exchange’s Protection Fund, meaning that user balances will not be affected.
2. Liquid Network Peg Malfunction (~$318.7M-$320M)
Earlier in the month, on September 6, the Bitcoin-linked layer-2 platform Liquid Network suffered an unusual settlement exploit. The developers of Elements software were able to create 4,000 unbacked L-BTC tokens, which they then used to convert to real Bitcoin using the native withdrawal channels. The Liquid Network exploit had a negligible impact on trading desks due to immediate mitigation efforts, but the incident risks delaying its adoption as a trusted piece of institutional infrastructure.
The Silver Lining: A Record Month for Fund Recoveries
The gross losses may seem significant, but September was also a historic month for crypto defense, mitigation, and asset recovery. Blockchain security teams, law enforcement, and white-hat interventions were able to return or freeze $273.2 million. This brought the net adjusted monthly loss to a more manageable $495.3 million.
Much of this recovery is related to the Liquid Network incident. The hackers, or “white-hat hackers” as they called themselves, worked in collusion with the developers to immediately return 3,400 BTC (about $285 million) directly to the network’s federation wallet.
There were also several smaller protocols that were able to retrieve lost money. An automated MEV bot exploit dubbed “yoink” saw its entire $7.81 million loss returned. In addition, Payment Processor V2 had been able to recover $3.4 million out of $6.6 million that it lost in an exploit earlier this month.