September was a brutal month for crypto security, with Bitget’s hot-wallet breach and a major Liquid Network exploit driving almost all of the damage. Depending on the tracker, gross losses came in at roughly $766.5 million to $768.4 million.
- Bitget and Liquid Network dominated September’s losses
- Gross losses are not the same as permanent losses
- Some stolen Bitcoin was returned, which changes the final tally
- The real weak points were wallets, vendors, and validation logic
PeckShield said September saw $766.5 million in losses across 55 major incidents, while CertiK counted 97 incidents and estimated $768.4 million in losses across the crypto sector. The two firms use different methodologies, so the close totals do not mean they measured the same thing in the same way. What it does show is that September was ugly by any reasonable standard.
The single biggest contributor was Bitget. The exchange initially said about $351.6 million had been affected after a Sept. 24 hot-wallet breach, then later revised the amount to roughly $388 million across 12 wallet addresses. Bitget also confirmed that about $387.5 million reached attacker-controlled addresses as investigators expanded the accounting.
A hot wallet is a wallet connected to the internet. That makes it useful for day-to-day transfers and withdrawals, but it also makes it a juicy target if the surrounding security is sloppy. Bitget said its cold wallets and private keys were not compromised, which is the important line between a contained operational breach and a full-blown vault disaster.
The exchange said the affected infrastructure included hot and warm wallets across Ethereum and other EVM networks, along with the XRP Ledger, Zcash, and Tron. Assets involved included ETH, XRP, USDT, USDC, ZEC, BNB, AVAX, and TRX. In plain English: the attacker didn’t need to break the blockchain. They went after the machinery around it.
Independent investigations by Mandiant and SlowMist pointed to compromised third-party security software as the likely access path. Bitget said the incident did not stem from a private-key leak. That distinction matters. If accurate, this was not a crypto-native magic trick. It was a trust-chain failure, the kind that starts with a tool people assume is protecting them.
Bitget’s response included a 5% bounty for qualifying help that directly results in assets being frozen or recovered. The exchange also said Circle and Tether had frozen roughly $318, 000 in stablecoins linked to the incident during the first days of the investigation. Its proof-of-reserves reporting showed a 131% total reserve ratio across 19 covered assets, which is useful for showing backing, but not a shield against bad operational security. A platform can be solvent and still get mugged.
That’s the part too many marketing departments conveniently forget. Proof of reserves can show that assets exist. It does not prove the keys are safe, the admin tools are hardened, or the vendor stack isn’t one bad dependency away from trouble. In crypto, “we’re backed” is not the same as “we’re secure.”
The other major hit came from the Liquid Network, which suffered a major attack on Sept. 6. This was not a simple wallet drain. Liquid later said a flaw in the Elements codebase, specifically its rangeproof verification cache, which is part of the software used to validate confidential transaction proofs, allowed a malicious transaction to pass validation.
Liquid Bitcoin, or L-BTC, is the tokenized Bitcoin representation used on Liquid. It is supposed to stay backed by real BTC. In this case, the vulnerability allowed roughly 4, 000 L-BTC to be created without the matching Bitcoin backing. From there, the attacker used Liquid’s peg-out process, the mechanism for moving assets from Liquid back to the Bitcoin main chain, to withdraw close to 4, 000 BTC in real Bitcoin.
CertiK placed the affected amount at 3, 998.5 L-BTC, worth about $318.7 million when the exploit occurred. Liquid’s federation reserve reportedly fell from around 4, 205 BTC to 197 BTC before recovery began. That is not a small bug. That is a protocol-level failure with an exit ramp attached.
But Liquid’s incident also shows why gross-loss headlines can be misleading if nobody explains the aftermath. On Sept. 7, the attacker returned 3, 400 BTC after onchain communication and negotiations with the Liquid team. Later assessments put about 602 BTC still outstanding. Earlier reporting cited in the materials said roughly 85% of the Bitcoin withdrawn from Liquid had been returned within a day.
That matters because the value of the returned coins changed with the market. At the time of repayment, the recovered Bitcoin was worth around $269 million, even though the original exploit value had been pegged at about $318.7 million. Same coins, different moment, different dollar figure. Crypto loves making simple things weird.
The same caution applies to Bitget. The exchange’s reported amounts reflect assets that reached attacker-controlled addresses, not necessarily the amount permanently lost forever. Some funds were frozen early. Some may still be traced or recovered. In crypto incident reporting, gross loss and permanent loss are not the same thing, and blurring them together is how headlines get louder than the facts.
Outside those two giant incidents, CertiK also identified smaller September losses, including roughly $7.8 million at Safe Wallet, around $6 million at DCENT, and about $5.9 million at Duelbits. None of those numbers is trivial. They just look tiny when the month’s biggest failures are measured in hundreds of millions.
Year to date, CertiK’s 2026 dashboard now shows 656 security incidents and roughly $2.68 billion in losses. Separate crypto.news research had already found at least $1.3 billion lost during the first eight months of 2026. September did not improve that picture. It made it worse.
Bitget said its remaining token, fiat, and P2P withdrawals were scheduled to resume at 08:00 UTC on Oct. 2 under a phased recovery plan. On the Liquid side, Blockstream deployed an emergency patch, block production resumed on Sept. 9, and peg operations were still suspended as of Sept. 29. The cleanup is always slower than the breach.
The bigger lesson is not that crypto is uniquely cursed. It’s that the weak points keep showing up where trust is concentrated: wallets, admin tools, security vendors, and validation code. Bitget’s breach was an operational failure. Liquid’s was a protocol validation failure. Different layers, same result, bad assumptions get expensive fast.
For a broader view of how these incidents fit into the sector’s security posture, check the Threat digest: 2026-09-09 and the broader incident index at Incidents · OAK. The pattern is not subtle: wallets, vendors, and validation logic keep biting the same people in slightly different ways.
That’s also why some platforms keep pitching “security” as if it’s a product brochure instead of an engineering discipline. Bitget, for example, has been pushing an AI-native universal exchange model, but AI branding is not a force field. If the underlying operational stack is sloppy, the shiny new buzzwords are just expensive wallpaper.
And when attackers do get caught, sometimes the outcome gets even weirder. The return of $21 million in Bitcoin to South Korea showed that negotiation, pressure, and traceability can still claw back funds, but it also exposed how fragile security assumptions remain across the sector. Crypto still has a bad habit of learning lessons the hard way.
Key takeaways
-
What made September 2026 so bad for crypto security?
Bitget’s hot-wallet breach and the Liquid Network exploit accounted for most of the month’s losses, pushing gross damage to roughly $766.5 million to $768.4 million. -
Why do PeckShield and CertiK show slightly different totals?
They use different methodologies and incident counts. The near-match is notable, but it does not mean they measured the same events in exactly the same way. -
Did Bitget lose $351.6 million or about $388 million?
Both figures appeared during the response. The lower number was the initial estimate, while the higher figure reflects later accounting that expanded the scope to more addresses and assets. -
Were Bitget’s cold wallets compromised?
No. Bitget said its cold wallets and private keys were not affected, which points to an operational breach rather than a total custody failure. -
Why is the Liquid exploit unusual?
It was a validation flaw, not a simple wallet theft. The bug allowed unbacked L-BTC to be created and then redeemed for real BTC through peg-out processing. -
Was the Bitcoin taken from Liquid all gone?
No. About 3, 400 BTC was returned after negotiation, leaving roughly 602 BTC still outstanding. Gross loss and permanent loss were not the same thing here. -
What does gross loss mean in crypto hacks?
Gross loss is the total value affected at the time of the incident. Permanent loss is what remains unrecovered afterward, which can be much lower if funds are frozen or returned.
September’s damage is a reminder that the most expensive failures in crypto are still usually boring ones: bad access control, weak vendor trust, and sloppy validation logic. The chain can be elegant. The surrounding systems can be a mess. And when that happens, nobody gets to hide behind buzzwords.