The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

$766 Million Lost to Crypto Hacks in One Month: What It Means for Your Custody

CertiK counts around $766.4 million in damage for September 2026, the highest monthly figure of the year. Two incidents carry more than 92 percent of it, and both hit a place where your balance could be sitting too.

Dark control desk of a security operations room at night, empty consoles, a single red warning light bathing the room in cold red
12 min read
Share:

The security firm CertiK published its monthly tally on September 30, 2026, and it reads worse than any month before it this year: crypto platforms and their users lost around $766.4 million in September through exploits and phishing. That is roughly three and a half times the August figure of $215 million, and it is at the same time the month with the highest number of individual incidents in 2026.

For an investor in Europe the sum is at first a number from another world. It gets interesting once you take it apart. The $766 million did not accumulate out of hundreds of small fraud cases but came, to more than 92 percent, from exactly two events. And both of them hit a place where your balance could be sitting too.

CertiK counts $766.4 million in damage for September 2026

CertiK puts the total damage at $766,451,111. Of that, around $270.6 million counts as returned or frozen, which leaves roughly $495.8 million actually lost. For comparison: in the first half of 2026 CertiK counted $1.32 billion across 344 incidents, a figure that was 46.8 percent below the first half of 2025. September has caught up with that calmer trend in a single month.

Exploit here means the abuse of a technical weakness in software or infrastructure, as distinct from phishing, where a user is talked into granting approval. The large sums almost always arise in the first case, the number of incidents grows in the second.

The market reacted remarkably little. Bitcoin traded at around $83,800 on September 30 according to CoinGecko data, practically unchanged from the previous day. That is a recurring pattern: hacks rarely move the price, they move the question of where your money sits.

Two incidents account for 92 percent of the monthly total

The single largest item is the attack on the exchange Bitget on September 24 and 25. The figures on the size of the loss diverge: CertiK and BleepingComputer name $387.5 million, while Bitget itself spoke of $351.6 million in an earlier statement. The range stands as long as no final accounting is available.

The second large item dates from September 6 and struck the Liquid Network, a Bitcoin sidechain run by the company Blockstream. Around $319 million to $320 million disappeared there, the equivalent of roughly 4,000 bitcoin. That makes the Liquid incident, on figures from TRM Labs, the largest single theft of the whole of 2026.

Close-up of a severed fibre-optic bundle, the cut fibre ends glowing turquoise in the dark
The most expensive damage of the month did not occur at an exchange but deep inside the software of a Bitcoin sidechain.

Liquid Network: a flaw in the rangeproof cache created uncovered bitcoin

On September 6 an attacker exploited a weakness in the open-source software Elements, on which the Liquid Network runs. What was affected was the way Liquid nodes cache the verification of so-called rangeproofs. A rangeproof is the cryptographic proof that a hidden amount lies within a valid range, meaning it is neither negative nor arbitrarily large. If that proof effectively drops away through a caching error, a transaction can pass verification even though its output amount is covered by no inputs at all.

That is exactly what happened: the attacker created synthetic, unbacked Bitcoin tokens on the sidechain and then redeemed them for real bitcoin. Blockstream has publicly described the flaw in its own assessment and halted the network; it remained paused as of the latest information.

The second part of the story is unusual. The attackers presented themselves as whitehats, negotiated with the Blockstream team over on-chain messages and, after the patch, sent back around 85 percent of the haul, some $272 million. Roughly $47 million stayed with them. Whether that remainder is a finder's fee or theft is a matter of perspective; legally it has not been settled.

Bitget hack: a zero-day in a third-party security product opened the wallets

The Bitget case is different. The exchange said the attackers had come in through previously unknown weaknesses in bought-in security products. A zero-day is a gap for which no patch exists at the time of the attack, because the manufacturer does not know about it either. The analysis firms SlowMist and Mandiant classified the compromised systems in their reports as security appliances; the earliest conspicuous activity dates to August 31.

Through those systems the attackers obtained, on Bitget's account, credentials for the internal network and were then able to falsify transaction data, so that the exchange's approval processes waved through the outflows from the hot and warm wallets. Affected were ETH, XRP, BNB, AVAX, USDT and USDC among others, across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base networks. Bitget attributes the attack, by its own account, to North Korean actors and bases that on IP patterns and on-chain analysis. Independent proof of that is not publicly available.

The exchange suspended withdrawals, set up a recovery bounty programme with a five percent reward and has since reopened operations step by step.

The month's attack vectors by size of loss

CertiK sorts the September damage by point of entry. The distribution is instructive because it shows where money is really lost:

  • Weaknesses in third-party services: $387.5 million
  • Faulty signature and proof verification: $324.7 million
  • Compromised wallets: $20.1 million
  • Errors in permission management: $13.3 million
  • Reentrancy bugs in smart contracts: $2.2 million

The top two lines correspond to the two major incidents. The third is the notable one: $20.1 million from directly compromised wallets, spread across considerably more cases. That is the category retail investors end up in: little headline, many people affected.

The $270.6 million return rate distorts the monthly balance

That a good third of the September total came back or was frozen sounds like an all-clear. It is, however, mostly the result of a special case. The lion's share of the return came from the Liquid incident, where the attackers transferred voluntarily. A rate like that is not a property of the system you can rely on.

In the Bitget case the recovery ran along a different route: analysis firms and infrastructure providers flagged and blocked partial amounts before they could be swapped. That works with stablecoins and with tokens that have a central controlling body, and it does not work with Bitcoin. The closer your holdings sit to freely transferable coins, the less this mechanism helps you.

A protection fund is not deposit insurance

After every large exchange incident the word protection fund comes up. Bitget points to such a fund of more than $300 million, and the state of payouts was moving again as of September 30, 2026. What matters is the legal classification: a protection fund is a voluntary reserve held by the company. It is not a legally secured promise and it is not deposit insurance.

Statutory deposit insurance in Germany covers bank balances in euros up to 100,000 euros per customer and institution. Crypto assets do not fall under it, not even when you hold them at a platform supervised in Germany. Anyone who believes their crypto balance is protected like a current account is wrong in an expensive place.

Counterparty risk with exchange balances, software wallet and hardware wallet

September delivers its own argument for each of the three usual forms of storage. On an exchange you hold a claim against a company; the keys are there. That is convenient, and it concentrates your risk at exactly the point that is most worthwhile for attackers. In the Bitget incident it was not your behaviour that decided the outflow but the software of a supplier you have probably never heard of.

A software wallet on your phone or in the browser gives you the keys back but shifts the risk onto your device. That is precisely where the $20.1 million from compromised wallets sits. A hardware wallet separates the key from the internet-capable device and demands a physical confirmation for every transaction. It does not help against a lost recovery phrase, and it does not help against a malicious approval you sign yourself.

A workable rule of thumb from the month of September therefore runs: what you want to move in the coming weeks sits on the exchange. What is meant to sit longer belongs under your own control. How far you go with that depends on the amount, not on enthusiasm for technology.

Two hands holding a small unbranded hardware device with a dark display above a wooden tabletop, a stamped metal plate lying beside it
The only form of custody that needs no external security product is your own.

What your exchange's MiCA licence covers and what it does not

Since January 1, 2026, only authorised providers may supply crypto asset services in Germany; the German transition period under the Crypto Markets Supervision Act ended at the close of December 31, 2025, and therefore earlier than in other EU states. A MiCA licence is the supervisory authorisation of a crypto service provider under the EU regulation on markets in crypto assets.

What that licence achieves is regularly overestimated. What is required are organisational minimum standards, the separation of client and own holdings, requirements for custody, complaint channels and reporting duties towards the supervisor. What the licence does not achieve: compensation when coins are stolen. An authorisation lowers the probability of a total failure through poor organisation, it does not replace insurance.

In practice that means the authorisation is a sensible minimum requirement when choosing a platform and no reason to leave larger sums sitting there permanently.

Stolen coins in the tax return: what the tax office accepts

One point goes missing after every hack: for tax purposes a theft is not a sale. That means a loss from stolen coins cannot simply be offset against gains in Germany, as it would be with a realised price loss. What is decisive is the documentation of the event, and in case of doubt you have to supply it yourself. Which pieces of evidence come into question we have gathered in a separate article on stolen coins and the tax office.

Anyone affected in September should secure the record now, regardless of the tax question: download the exchange's transaction statements, keep the correspondence with the provider, note the time of the incident. Those documents can no longer be obtained later if a platform shuts down.

What October brings for holders in Europe

Two things remain open. First, the final accounting at Bitget: as long as the range between $351.6 million and $387.5 million stands, the September total itself is only as precise as its largest single item. Second, the restart of the Liquid Network, which was still halted as of the latest information. Anyone holding positions there cannot reach them until it is released.

For everyone else the lesson of the month is unspectacular. Neither of the two major incidents failed on weak passwords; both failed on software deep in the infrastructure. Against that class of error you can do nothing except limit how much of your holdings is exposed to it at all.

Crypto hack losses: What to take away

  1. Count up how much is sitting with third parties. Add up all balances on exchanges and at brokers and compare the total with what you really need there for short-term trades. If you are questioning the platform anyway, an overview of the regulated crypto exchanges with an EU authorisation helps.
  2. Pull out the long-term part. Move what you want to hold for months into your own wallet and test the route with a small amount first. Which programs come into question and where their limits lie is shown by the comparison of software wallets; from larger sums on, the route leads to hardware.
  3. Document the holdings before anything happens. Download the transaction statements of your platforms now and file them with a date. A portfolio tracker or tax tool takes that over continuously and makes you independent of whether an exchange is still reachable in an emergency.

(As of September 30, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Sources: Blockstream, Liquid Network Security Incident Assessment and BleepingComputer on the Bitget attack.

Frequently asked questions about crypto hack losses

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

Related articles

Which topics should we dive deeper into?

Select what genuinely interests you. Your picks feed directly into our editorial planning.

Crypto news that's actually worth your time.

Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.

Subscribe

More on this topic

View All

More from CryptoTicker