Losses from security incidents across the digital asset sector reached 766.5 million dollars during September 2026. According to the monthly alert from PeckShield, a total of 55 major exploits caused this monthly outflow, establishing September as the most damaging month of the year.
#PeckShieldAlert In Sep. 2026, the crypto industry experienced 55 major hacks, resulting in total losses of $766.49M – a ~462% month-over-month increase from August's $136.3M.
The #Bitget incident (~$387M) and #LiquidNetwork (~$320M, with $285M returned) have jumped to #1 & #2… pic.twitter.com/abePPGX7Y5
— PeckShieldAlert (@PeckShieldAlert) October 1, 2026
Separately, blockchain security firm CertiK documented 97 distinct incidents on October 1, 2026. The firm estimated overall losses at 768.4 million dollars, reflecting a significant increase compared to exploit numbers registered during August across Web3 ecosystems.
Both security teams reported that September established the highest monthly theft total of 2026. The stolen capital was heavily concentrated in two specific platform breaches that together represented over 90% of total losses recorded during the period.
CertiK stated on September 30, 2026, that the sudden jump in exploited capital showed how rapidly the threat landscape shifts. The firm noted that institutional custodians face mounting exposure as attack techniques adapt to existing defense protocols.
Infrastructure Breaches and Major Exchange Outflows
The primary contributor to September’s losses was the cryptocurrency exchange Bitget. During the security exploit against Bitget detected on September 24, 2026, malicious actors drained 388 million dollars from hot and warm wallet systems.
Bitget corporate representatives stated that cold storage reserves remained completely offline and unaffected. Chief executive Gracy Chen announced a phased timeline that resumed Bitcoin withdrawals on September 28, with Ether and stablecoins scheduled to follow across subsequent days.
The second major security event struck the Liquid Network, where an exploit compromised approximately 320 million dollars in digital assets. The incident immediately entered the records as one of the largest single thefts involving sidechain infrastructure in 2026.
A substantial portion of that capital was subsequently recovered through direct negotiations. Official reports indicated that more than 270 million returned to protocol contracts, reducing the net financial damage suffered by the network’s liquidity pools.
Decentralized Incidents and Annual Cumulative Data
Multiple smaller decentralized platforms recorded separate drainage incidents during September 2026. The vulnerability pattern mirrored the earlier exploit on Cronos from August 30, where 9.19 million dollars escaped before network validators halted and rolled back the chain.
Among the secondary breaches documented in September, Safe Wallet reported unauthorized outflows totaling 7.8 million dollars. Similarly, hardware wallet provider DCENT identified a compromise that resulted in 6 million dollars drained from user accounts.
Gaming platform Duelbits also sustained losses, reporting that attackers extracted 5.9 million dollars before access was contained. These smaller incidents demonstrated that vulnerabilities spanned both personal custodial interfaces and high-volume entertainment platforms.
Cumulative data recorded throughout 2026 highlights persistent vulnerability across digital asset ecosystems. According to the security dashboard from CertiK, the industry has logged 2.68 billion dollars lost across 656 recorded security incidents year-to-date.
The 2.68 billion total illustrates that smart contract audits do not eliminate operational risk once applications deploy at scale. Protocol logic flaws and compromised private keys remain the primary attack vectors exploited by threat actors across decentralized finance.
Forensic analytics teams continue tracking the recipient wallets connected to the stolen Bitget and Liquid Network tokens. On-chain transaction flows indicate that portions of those assets were routed through cross-chain bridge contracts and decentralized automated liquidity pools.
Both PeckShield and CertiK are scheduled to publish their full third-quarter security reports before October 15, 2026. Those reviews will detail unresolved exploit vectors and indicate final recovery totals for all decentralized finance networks.
This article is for informational purposes only and does not constitute financial advice.

