Crypto lost roughly $766 million to exploits, thefts and phishing in September — the worst month of 2026 by both total losses and incident count, according to tallies published September 30 by two blockchain security firms that worked independently and arrived within $2 million of each other.
CertiK's month-end incident graphic listed losses of $766,451,111, of which $270,610,532 was classified as returned or frozen. PeckShield, counting 55 major incidents rather than CertiK's broader 97, put the figure at $766.5 million, Cointelegraph reported. The near-identical bottom lines from separate methodologies make the headline number unusually solid for this kind of statistic.
"September was a stark reminder of how quickly the threat landscape can shift," CertiK said in a statement Wednesday.
Two Incidents Drove 92% of the Damage
| Rank | Incident | Date | Loss (USD) |
|---|---|---|---|
| 1 | Bitget | September 24 | $387.5M |
| 2 | Liquid Network | September 6 | $318.7M |
| 3 | Safe Wallet users | Mid-September | $7.8M |
| 4 | D'CENT | September 15–20 | $6.0M |
| 5 | Duelbits | September 24 | $6.0M |
The Bitget hot-wallet theft and the Liquid Network breach together account for more than 92% of the month's confirmed losses. The returned-or-frozen line is dominated by the roughly $270 million in bitcoin that Liquid's whitehat moved to safety — a recovery path now under dispute on Immunefi. Further down the table: ShopLink at $4.7 million, Astroport at $4.4 million and Nostra Finance at $3.5 million.
By platform category, centralized exchanges bore $387.5 million and base-layer/sidechain infrastructure $325.1 million — while DeFi protocols accounted for just $13.3 million and individuals $18.5 million.
The Attack Types Behind the Numbers
The attack-type breakdown is the most telling part of the report. "Third Party Service" — the vector in the Bitget breach, where a third-party security product was compromised — accounts for $387.5 million on its own. "Invalid Signature," the class of proof- and signature-validation failure behind the Liquid incident, adds $324.7 million. Wallet compromise contributed $20.1 million and improper permission control $13.3 million.
Reentrancy — historically the signature smart-contract bug — accounted for about $2.25 million, barely a rounding error. September's damage came from operational infrastructure and validation logic, not from the classic DeFi exploit classes that monthly reports used to catalog.
Context: A Year Already Running Hot
September's gross total is more than 3.5 times August's $215 million, and even after subtracting the $270.6 million returned or frozen, the residual ~$496 million exceeds August's entire gross figure. CertiK's dashboard now shows 656 security incidents in 2026 with total losses of $2.68 billion year-to-date, on top of the $1.32 billion the firm counted in its Hack3D report for the first half.
The throughline for operators: the two megabreaches of September were not smart-contract failures. One ran through a compromised third-party product inside an exchange's stack; the other through a validation flaw in network infrastructure. Custody-side security — vendor chains, privileged access, proof verification — is where the year's losses are concentrating.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.