Crypto-related hacks and exploits affected approximately $1.174 billion in assets between July 1 and September 30, 2026, a sharp increase from the $955 million recorded across the entire first half of the year, according to tallies reported by Finbold and TokenPost, with corroborating coverage at cryptonews.net.
One caveat belongs in the first paragraph, not the last: the figure measures the gross value of assets affected at the time each incident occurred. No definitive net-loss total was established for the quarter. In several of the largest incidents, funds were returned, recovered or never left user accounts — which makes the $1.17 billion a measure of attack surface, not of money gone.
The Five Incidents That Made the Quarter
Bitget (September 24). The exchange breach was initially estimated at $351.6 million after unauthorized transfers were detected at 18:31 UTC, later revised to approximately $387.5 million once assets on Zcash and Tron were included. The breach involved hot and warm wallets; cold wallets remained secure and user account balances were unaffected. Bitget's position at the time: "User funds are safe."
Liquid Network (September 6). Approximately 4,000 BTC was released through the Bitcoin sidechain's peg-out mechanism at 15:53 UTC — Bitcoin that was not backed by reserves. Approximately 3,400 BTC was returned the following day, making this the quarter's largest partial-recovery case.
Tectonic (August 30). The lending protocol exploit involved approximately $120.4 million in borrowed assets after the attacker manipulated the price of TONIC by roughly 195 times. Approximately $9.19 million that left Cronos before the chain halted remains unrecovered.
Coldcard (from July 30). A firmware flaw in the hardware wallet weakened seed generation and led to the draining of approximately 1,816 BTC from more than 5,200 addresses. The quarterly tally valued the incident at roughly $100 million, while a separate estimate put the drained Bitcoin at about $116 million — a spread that illustrates how valuation timing moves these numbers.
AFX Bridge (July 22). The transfer of 24.15 million USDC followed a compromise of validator infrastructure.
Why Gross Tallies Understate and Overstate
Gross affected-value accounting cuts both ways. It overstates final losses when funds are returned, as with Liquid's 3,400 BTC, or never touched, as with Bitget's cold storage. It understates the true cost when it ignores downstream effects: service outages, depegs triggered by stolen collateral, and the operational cost of chain halts like Cronos's response to Tectonic.
The quarter also illustrates reporting lag. Bitget's revision from $351.6 million to $387.5 million happened days after the initial estimate; the Coldcard valuation spread never fully closed. Finbold notes 11 known hacks in the first nine days of October — a pace that, if sustained, would make Q4 worse than Q3 before the month is half over, and one that ensures the 2026 tally will keep being revised upward after the fact.
For defenders, the quarter's lesson is structural rather than numeric: the largest incidents split evenly between exchange infrastructure (Bitget), blockchain infrastructure (Liquid, AFX Bridge), protocol logic (Tectonic) and hardware (Coldcard). No single layer of the stack concentrated the losses — which is another way of saying no single layer of the stack can be trusted to prevent them.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.