$1.26 Billion in Three Months: Crypto Hacks Hit Their 2026 High
The security firm CertiK counts around $1.26 billion in damage from 247 incidents for the third quarter of 2026. September was the worst month of the year with 99 cases, and this is the background and what it means for your custody.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Between July and September 2026, attackers pulled roughly $1.26 billion out of the crypto market. The figure comes from the security firm CertiK, which counted 247 security incidents in the third quarter. That means almost half as much drained away in three months as in the whole year to date, for which CertiK arrives at around $2.68 billion.
For you as an investor in Germany, this is not an abstract statistic. The big cases of the quarter did not hit exotic niche projects but one of the largest trading platforms in the world and an established sidechain. This piece puts the figures in context, separates the two competing counts from one another, and shows where you can genuinely check your own custody.
What CertiK counted for the third quarter of 2026
CertiK keeps a running tally of attacks on blockchain protocols, trading venues and wallet infrastructure. For the third quarter of 2026 the firm puts the damage at around $1.26 billion from 247 incidents. On the same count, the second quarter stood at $819.4 million from 219 incidents. The total has therefore risen by a good half, the number of cases by just under thirteen percent.
That ratio is the real finding. There were not substantially more attacks, but the successful ones were markedly larger. Average damage per incident climbed from around $3.7 million to about $5.1 million. Anyone who leaves crypto assets on a platform shares their risk with every other customer of that same platform, and that is precisely where the large sums sit.
What CertiK counts as a security incident
A security incident in this tally is any case in which crypto assets leave their owner without the consent of the person entitled to them. That covers three very different things: the exploit, meaning the abuse of a flaw in a protocol's program code; key theft, where attackers obtain private keys or approval rights; and fraud, where users are talked into granting access themselves. Price losses, insolvencies and frozen withdrawals do not count.
The distinction matters because it determines the countermeasure. Against a flaw in the code of someone else's protocol there is little you can do as a user other than avoid the protocol. Against key theft and approval fraud you can do a great deal.
September 2026: 99 incidents and the highest monthly loss of the year
September carried the bulk of the quarterly damage. Depending on the count, between $766 million and $769 million drained away, spread across 99 larger incidents. That is the highest monthly figure of 2026 and at the same time the highest case count since February 2025. Against August, which was unusually quiet, it amounts to a rise of around 462 percent.
The previous peak month of the year was April at a little over $648 million, driven at the time by the attack on KelpDAO. September has surpassed that figure even though the year had been regarded as comparatively calm until then.
CertiK itself framed the month on its own channel in these terms: September was a clear reminder of how quickly the threat picture can shift; with losses and case numbers at the year's high, the month underlined that security is needed at every level. The assessment comes from the firm that also collects the figures, which is worth keeping in mind, because CertiK sells audits of program code.
Bitget and Liquid Network: the two largest single cases of the quarter
Two cases together account for almost half of September's damage. Around $387.5 million fell on the trading platform Bitget. At Liquid Network, a sidechain built on Bitcoin, it was around $320 million, of which about $285 million flowed back according to the analytics firm Chainalysis.
Bitget then reopened withdrawals in stages: first Bitcoin, then Ether, then stablecoins, and finally the remaining routes. That a platform of this size needs several days to restore normal operation is the practical part of the news. For that period you cannot reach your balance, regardless of whether your own account was affected at all.
Recovered funds and the gross figure
The $1.26 billion is a gross figure: what is recorded is what drained away, not what remained lost in the end. In the Liquid Network case the large majority came back, which noticeably lowers the quarter's actual net damage. Returns like this happen when attackers cannot move stolen funds because analytics firms and trading venues flag the addresses. Do not rely on it: in most cases the money stays gone.

Two counts, two totals: $766 million to $769 million in September
Two numbers are in circulation for the September figure. CoinDesk cites CertiK for $768.5 million, while other analyses of the same data arrive at $766.49 million. The gap of around $2 million sounds wide, but at a total of this order of magnitude it is a rounding and cut-off effect.
Discrepancies like this arise because damage totals are valued in dollars while the stolen assets are held in cryptocurrencies. Depending on whether the price at the moment of the attack, at month end or at the time of the analysis is applied, the result shifts. Late reports add to it: an incident on September 29 may only be fully quantified in October.
For you that means taking such numbers as an order of magnitude, not as a measurement. The statement that September was the worst month of the year holds. The second decimal place does not.
Stolen keys instead of broken cryptography: the most common route of attack
The notion that cryptocurrencies are being cracked misses the reality. The underlying encryption holds. What breaks, regularly, is the layer in front of it: the management of keys, the approval of transactions, employee access to internal systems. We have set out this finding in detail for DeFi hacks; it applies to centralised platforms in exactly the same way.
A private key is the string of characters that allows crypto assets at an address to be moved. Whoever holds it controls the assets, with no password, no confirmation prompt and no way of reversing the entry. That is precisely why attackers go for it and not for the mathematics behind it.
Phishing and approval rights
The second major route runs through approvals. When you use a decentralised application, you grant its smart contract the right to move tokens out of your wallet. That approval stays in place until you withdraw it, including long after you have stopped using the application. An unlimited approval to a contract that is later compromised is an open door.
In practice that means granting approvals with an amount limit rather than without one, and clearing out old approvals regularly. The common block explorers offer an overview of the rights you have granted.
Centralised exchange or your own wallet: where your risk actually sits
The quarterly figures show both risks side by side. If your coins sit on a trading platform, you carry its counterparty risk: if it is attacked, your balance depends on its reserve cover and on its determination to absorb the damage. If you hold the assets yourself, you carry the risk alone, and a lost key is final, but no outside incident can reach you.
There is a middle road. Anyone who trades regularly leaves the trading balance on the platform and withdraws the long-term holding. For the part that is withdrawn, a hardware wallet is the usual instrument; which devices differ in what is set out in our hardware wallet comparison. What matters is less the model than whether you keep the recovery words safely and offline.
What self-custody takes off your hands and what it does not
Self-custody, meaning holding assets under your own responsibility, takes the counterparty risk off your hands. It does not take the fraud risk off your hands. Anyone who is induced to sign a malicious transaction loses their coins from a hardware wallet too. The device protects the key, not the decision.

MiCA and BaFin: the duties a provider in Germany has to meet
Since July 1, 2026 the EU regulation on markets in crypto assets, MiCA for short, has applied without restriction; that was the day the transition period ended for providers previously operating under national law. Anyone who holds crypto assets for customers in Germany or offers trading has since needed an authorisation and is supervised by BaFin or another European authority.
For custody, that above all means an obligation to segregate: customer holdings are to be kept separate from the provider's own assets so that they do not fall into the estate if it becomes insolvent. Added to that are requirements for internal controls and for documenting key management. We have put together an overview of which duties apply in detail.
An authorisation is not insurance against attacks, and some of the quarter's cases involved regulated houses. What it does change is the starting position when something happens: there is a competent supervisor, a legal entity you can get hold of, and documented segregation of holdings. Which providers are authorised for the German market is shown by our overview of regulated crypto exchanges.
Regulated crypto exchanges for the German marketCompensation after a hack: the legal position in Germany
Whether you get money back after an attack hangs on two questions: where were the assets held, and who is answerable for the failure? If they were with an authorised custodian, its contractual and regulatory duties apply, and the segregation of customer holdings is meant to ensure that your claim does not founder on the provider's insolvency. If they were in your own wallet, there is no one to claim against except the perpetrator.
In practice, large platforms have often made good losses out of their own funds in recent years, voluntarily and as a business decision, not because of a statutory guarantee. There is no deposit protection scheme for crypto assets of the kind that covers bank balances. Plan with the way you split your holdings, then, rather than with a refund.
For tax purposes a theft is not a disposal. Anyone affected should nevertheless document the incident without gaps: the time, the addresses involved, the correspondence with the provider, the report to the police. Without those records, neither a civil claim nor a tax treatment can be substantiated later on.
Cross-chain bridges as an attack surface: the NEAR Intents case
The quarter ended with a case that shows the weak point well. The cross-chain service NEAR Intents confirmed an attack on its infrastructure on October 1, 2026 with damage of around $3.8 million; deposits and withdrawals across twelve networks were affected. The service announced that it would compensate those affected in full. The price of the associated token fell back sharply as a result; the context for that is on our NEAR forecast page, and we described the sequence of events in detail on October 1.
A cross-chain bridge is a service that moves assets between separate blockchains. Because the networks do not know one another, the bridge locks the assets on one side and issues an equivalent on the other. That intermediate step is a place of custody in its own right, and therefore a worthwhile target.
What that means for the way you use bridges
Bridges are not a storage place. Anyone moving assets across chains should complete the process and then take the assets to where they are meant to sit. A balance left for weeks in a bridge contract or an intent service carries a risk with no return to match it.
Crypto Hacks: How to Proceed Now
- Separate your trading balance from your long-term holding. Leave on the platform only what you will actually move in the coming weeks. The rest you withdraw into custody of your own; the differences between the devices are set out in the hardware wallet comparison.
- Check your provider's authorisation. Look up whether your trading venue holds a MiCA authorisation for the German market and who supervises it. You will find an overview sorted by supervisory status among the regulated crypto exchanges.
- Clear out your approvals. Go through the token approvals your wallet has granted and withdraw what you no longer need. The duties that come on top on the provider's side are set out in our overview of the MiCA licensing obligations.
(As of October 2, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Frequently asked questions about crypto hacks
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- $766 Million Lost to Crypto Hacks in One Month: What It Means for Your Custody
- Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
- Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
- Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
- Wave of Crypto Hacks and Exploits Hits Influencers and Memecoins: WATCH OUT!
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
September 3, 2026 10:21 AM

Bitcoin Lost in a Wallet Hack: What Tax Applies in Austria?
Bitcoin lost to hackers? In Austria, the theft of privately held coins generally does not create a capital loss you can use for tax. Only a later payout can change that.
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
April 27, 2026 10:30 AM

Win $5,000 in BTC: Tangem Launches Exclusive 2026 Prize Draw
Tangem announces a massive prize draw with $5,000 in BTC and iPhone 17s up for grabs. Secure your crypto and enter today using our exclusive link.
December 22, 2020 3:49 PM

Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
Ledger, a cryptocurrency wallet provider has encountered a data breach. The official Twitter account of the hardware wallet tweeted that they have been alerted to the dump of a client database.
August 22, 2026 4:16 PM

Stolen Crypto: Where You Actually File a Report and What Counts in the First Hours
After a theft most people google first and preserve the evidence last, when the right order is the other way round. What you have to record in the first hours, where private individuals actually turn, and where the limit of what is possible lies.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
February 14, 2025 8:40 PM

Here's How to Gift Cryptos this Valentine’s Day
This Valentine’s Day, surprise your partner with a gift that grows in value—cryptocurrency! Here's how to send crypto or gift a secure hardware wallet for a truly modern expression of love.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
December 28, 2018 3:02 PM

How To Use a Trezor Wallet?
Trezor is a hardware wallet which gives exceptional security for managing Bitcoin and other cryptocurrencies private keys.It incorporates and deposits personal keys securely and enables users to carry trade without an Internet link. Trezor grants its users with numerous benefits, […]
May 2, 2024 7:23 AM

Top 3 Crypto Hacks that Made Millions
The world of cryptos has seen its fair share of hacks, with some resulting in staggering losses. Here are the biggest 3 hacks since 2020.
September 30, 2026 1:23 PM

NEAR Intents Blocks $50 Million From the Bitget Hack: Why THORChain Let the Swaps Through
A cross-chain protocol says it stopped more than $50 million in transfers from the Bitget attack and froze $503,000. The case shows who can halt funds in transit and what that means for your custody.
September 24, 2026 10:11 PM

Bitcoin Price Prediction: What to Check on Levels, Holding Period and Leverage Before the October 28 Rate Decision
Bitcoin is trading at around $83,800, a third below its October 2025 high, while the sentiment index reads greed. Which dates, levels and deadlines over the coming weeks really decide your net gain, and which of them you steer yourself.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
August 22, 2026 4:13 AM

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
August 4, 2026 1:21 PM

Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
April 21, 2026 11:15 AM

Breaking: Arbitrum Security Council Freezes $71M in ETH Linked to KelpDAO Exploit
The Arbitrum Security Council has frozen 30,766 ETH tied to the KelpDAO hack, sparking a fierce debate over decentralization and emergency powers in DeFi.
May 18, 2026 8:15 AM

Bitget Review 2026: Is Bitget a Good Crypto Exchange? What You Need to Know
Explore the key insights and safety considerations of trading on Bitget. Make informed decisions before you start trading. Read the full review now!
May 15, 2024 12:04 PM

Crypto Scams: How to Protect Your Cryptos?
With the rise of crypto scams, and while international efforts are still working to combat these threats and protect investors, some recent tactics have been identified, and here is your full guide.
June 18, 2025 12:05 PM

BREAKING: Israeli-Linked Hackers Allegedly Wipe Out Nobitex Exchange
Nobitex, Iran’s top crypto exchange, has reportedly lost $48.65 million in a massive hack. Linked to Israeli cyber group Predatory Sparrow, the attack allegedly wiped out 95% of the platform’s assets.
February 21, 2025 9:55 PM

Bybit Hack Revealed: Here's the Mastermind Behind the $1.46 Billion Theft
The Bybit hack has been traced back by the blockchain investigator ZachXBT, with conclusive evidence linking the hackers to the $1.46 billion theft. Full details revealed...
December 26, 2024 1:08 PM

BGB News: Bitget Token Reaches New ATH Amid Market Momentum
Bitget Token (BGB) defies the market downtrend, hitting a new ATH of $7.32. What's driving this 368% surge and what the future holds for this top-performing cryptocurrency?
June 28, 2026 8:12 PM

Polymarket Hack: $3.1M Stolen as Prediction Market Hype Faces Its Biggest Test
Polymarket hack shocks prediction markets as $3.1M is stolen from 11 wallets. Is the sector ready for mainstream adoption?
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
More from CryptoTicker

