September 2026 was the worst month of the year for crypto hacks. PeckShield counted 55 major incidents and $766.5 million stolen, while CertiK logged 97 cases and $768.4 million. Clients of centralized platforms feel it most, because the vault itself gets breached.
The month's tally: 55 incidents and $766.5 million
The two security firms count differently but land on nearly the same sum. PeckShield takes only major cases, CertiK also records smaller ones, so its incident count is almost twice as high. The gap in dollars is under $2 million. Both firms saw a clear jump from August.
The yearly picture is harsher. CertiK's data shows 656 incidents since the start of 2026, with $2.68 billion lost. September alone supplied almost 29% of that.
Bitget and Liquid took almost everything
The $388 million breach of Bitget and the $320 million attack on the Liquid Network add up to $708 million, about 92% of the monthly losses. The other 53 cases in PeckShield's count look small. Safe Wallet lost $7.8 million, DCENT $6 million and Duelbits $5.9 million.
Some of the Liquid money did come back. Reports put the returned amount above $270 million.
Where the stolen money goes
The Bitget attackers are in no hurry to cash out. CoinDesk reports they moved about $4 million into Zcash's private pool, and tracing such funds is much harder. According to Decrypt, NEAR had earlier rejected swaps worth roughly $50 million.
SlowMist researchers traced the attack preparation back to August 31. Suspicious activity involving a zero-day vulnerability, two security products and a custom withdrawal tool began weeks before the theft. The exchange did not notice.
Lawyers are already debating whether THORChain developers could be held liable, since the protocol does not block addresses tied to the $387.5 million hack. Crypto lawyer Yuriy Brisov calls the question complicated.
Risks for people who keep funds on exchanges
Bitget is returning to normal operations. Bitget CEO Gracy Chen says the protection fund created in 2022 absorbed the financial hit and now stands at $309 million. Not every platform has a cushion like that.
- A protection fund works only if it is big enough and the exchange is willing to use it.
- Private pools like Zcash let thieves delay laundering, so the odds of recovery fall with each week.
- Self-custody is no cure either: MetaMask exited its Ethereum validators and is investigating an internal security incident, though it sees no direct threat to wallets so far.
For Ukrainians who keep USDT on exchanges between P2P trades, this is a reason not to leave more there than the next operation needs. Long-term holdings are better moved to hardware wallets with offline keys.
The bottom line for the market
September showed that the biggest losses come not from smart contract bugs but from breached services with large balances. Two incidents made up over 90% of the damage. Bitcoin holds near $84,000 and these stories do not stop it, but they hit the reputation of trading venues every time.




Comments
Your email address will not be published. Required fields are marked *