Crypto lost roughly $766 million to exploits, thefts and phishing in September — the worst month of 2026 by both total losses and incident count, according to tallies published September 30 by two blockchain security firms that worked independently and arrived within $2 million of each other.

CertiK's month-end incident graphic listed losses of $766,451,111, of which $270,610,532 was classified as returned or frozen. PeckShield, counting 55 major incidents rather than CertiK's broader 97, put the figure at $766.5 million, Cointelegraph reported. The near-identical bottom lines from separate methodologies make the headline number unusually solid for this kind of statistic.

"September was a stark reminder of how quickly the threat landscape can shift," CertiK said in a statement Wednesday.

Two Incidents Drove 92% of the Damage

Rank Incident Date Loss (USD)
1 Bitget September 24 $387.5M
2 Liquid Network September 6 $318.7M
3 Safe Wallet users Mid-September $7.8M
4 D'CENT September 15–20 $6.0M
5 Duelbits September 24 $6.0M

The Bitget hot-wallet theft and the Liquid Network breach together account for more than 92% of the month's confirmed losses. The returned-or-frozen line is dominated by the roughly $270 million in bitcoin that Liquid's whitehat moved to safety — a recovery path now under dispute on Immunefi. Further down the table: ShopLink at $4.7 million, Astroport at $4.4 million and Nostra Finance at $3.5 million.

By platform category, centralized exchanges bore $387.5 million and base-layer/sidechain infrastructure $325.1 million — while DeFi protocols accounted for just $13.3 million and individuals $18.5 million.

The Attack Types Behind the Numbers

The attack-type breakdown is the most telling part of the report. "Third Party Service" — the vector in the Bitget breach, where a third-party security product was compromised — accounts for $387.5 million on its own. "Invalid Signature," the class of proof- and signature-validation failure behind the Liquid incident, adds $324.7 million. Wallet compromise contributed $20.1 million and improper permission control $13.3 million.

Reentrancy — historically the signature smart-contract bug — accounted for about $2.25 million, barely a rounding error. September's damage came from operational infrastructure and validation logic, not from the classic DeFi exploit classes that monthly reports used to catalog.

Context: A Year Already Running Hot

September's gross total is more than 3.5 times August's $215 million, and even after subtracting the $270.6 million returned or frozen, the residual ~$496 million exceeds August's entire gross figure. CertiK's dashboard now shows 656 security incidents in 2026 with total losses of $2.68 billion year-to-date, on top of the $1.32 billion the firm counted in its Hack3D report for the first half.

The throughline for operators: the two megabreaches of September were not smart-contract failures. One ran through a compromised third-party product inside an exchange's stack; the other through a validation flaw in network infrastructure. Custody-side security — vendor chains, privileged access, proof verification — is where the year's losses are concentrating.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.