Two months competed for the title of 2026's worst year for crypto theft. September just settled the question with a week to spare.
With Bitget's confirmed $351.6 million hot-wallet breach on September 24, reported gross losses for the month have pushed above $684 million, CryptoSlate reported — surpassing April's $646.9 million, which was itself dominated by two incidents: the Drift exploit (roughly $270 million) and the KelpDAO attack (about $292 million), together accounting for some $577 million of that month's total.
How the Month Stacked Up
DeFiLlama had recorded about $331 million in losses across 17 September incidents before the month's final week. The subsequent cascade tells the story of a discipline problem, not a single point of failure:
- Bitget, $351.6 million (Sept 24) — hot and warm wallet compromise at a major exchange; withdrawals frozen; losses pledged against the exchange's $464 million protection fund. Full coverage.
- Liquid Network, ~$320 million (early September) — tokens created out of thin air on the Bitcoin sidechain; the network halted, then resumed with peg-outs frozen while on-chain negotiation with the attacker played out.
- SingularityNet bridge, ~$260 million and widening (Sept 23) — AGIX/WMT-X losses expanded as investigators traced additional flows.
- D'CENT app wallet flaw, 11.75 million XRP across 6,678 wallets (Sept 24) — a supply-chain-style compromise hitting end users in six waves.
- Duelbits, ~$7 million (Sept 24) — suspected private key compromise at a crypto casino. Full coverage.
- The long tail: Nostra/Pragma oracle failures on Starknet, the MultiversX VM atomicity exploit, the Cosmos Hub governance attack, Fetch.ai/NuNet's $2 million theft, and others.
The Shape of the Problem
Three observations stand out from the month's data.
First, key management, not smart contracts, did most of the damage. The two largest September incidents — Bitget and Duelbits — both involve suspected private key compromises of hot wallet infrastructure, not consensus bugs or DeFi logic errors. The year's earlier mega-breaches skewed the same way: Drift began with attackers gaining administrative control.
Second, gross figures overstate final losses, by design of the response. Bitget's loss is backed by a protection fund; Liquid's frozen peg-outs and white-hat negotiations may claw back much of the sidechain damage; flagged stablecoin addresses routinely get frozen before they reach cash-out. The April comparison uses the same gross basis, so the ranking is fair, but the net damage will take months to settle.
Third, the year is running at a pace the industry has seen before. TRM Labs reported in September that 2026 had already recorded roughly 333 hacking incidents involving approximately $1.73 billion in stolen assets at the time of its analysis — before the final week of this month. That trajectory approaches 2025's full-year total of $2.72 billion, per Chainalysis data.
What to Watch
The near-term markers are concrete: Bitget's promised full incident report within 24 hours of the breach (root cause and corrective measures), the resolution of Liquid Network's peg-out freeze, and whether the consolidated attacker wallets from this week's incidents move toward bridges or exchanges where freezes are possible.
The structural marker is older: exchanges that survived 2025 learned that protection funds, withdrawal delays and multi-layer key isolation are cheaper than the alternative. September's ledger is the cost of re-learning that lesson at scale.
TrustGrade tracks incident history and security posture for exchanges and protocols. Verified trust data: trustgrade.ai.