Thu. Oct 1st, 2026

PeckShield Counts $766.5M Stolen Across 55 Major Crypto Security Incidents in September

ByJohan Shamshad

October 1, 2026 #PeckShield
Crypto Hack

Crypto security losses surged to $766.5 million across 55 major hacks and exploits in September, according to a new monthly tally from PeckShieldAlert, making September the costliest month for crypto security incidents in 2026 so far.

The total was overwhelmingly driven by two events: the approximately $387.5 million Bitget breach and the roughly $320 million incident affecting Bitcoin sidechain Liquid Network. Together, the two accounted for around 92% of PeckShield’s gross September loss figure.

A separate calculation from blockchain security company CertiK landed remarkably close in dollar terms despite using a different incident methodology. CertiK recorded 97 security incidents and approximately $768.4 million in losses during September.

The similarity between the two dollar estimates is notable because their incident counts differ sharply. PeckShield’s dataset focuses on 55 major hacks, while CertiK recorded 97 security incidents under its broader tracking framework. The figures therefore should not be treated as identical datasets, but they point to the same conclusion: September was an unusually expensive month for crypto security.

Bitget and Liquid Accounted for Roughly 92% of September Losses

September’s headline figure was highly concentrated rather than the result of dozens of equally damaging exploits.

Bitget alone accounted for roughly half of PeckShield’s monthly total. The exchange ultimately valued its September 24 security breach at approximately $387.5 million after expanding its initial accounting to include additional Zcash and Tron transfers.

Investigators later determined that the attackers did not steal Bitget’s private keys. Instead, forensic work found evidence that a zero-day vulnerability in a third-party security product provided an entry point into internal infrastructure, followed by forged withdrawal instructions that reached the exchange’s wallet system.

Subsequent investigation has made the breach look more serious from an operational-security perspective. SlowMist found evidence suggesting the Bitget attackers were inside compromised infrastructure weeks before the theft, with malicious activity dating back to August 31.

Bitget has since progressively restored customer services, including USDT withdrawals following the $388 million incident. The exchange says customer balances were unaffected and that its Protection Fund will absorb the financial impact.

The Liquid Network incident contributed another approximately $320 million to September’s gross tally. Attackers exploited a flaw in the Elements software used by the Bitcoin sidechain, allowing them to create roughly 4,000 unbacked L-BTC and redeem the synthetic Bitcoin for real BTC held in Liquid’s federation reserve.

The unusual part came afterward. The actors described themselves as white hats and ultimately returned approximately 3,400 BTC, or roughly 85% of the Bitcoin withdrawn, after the vulnerability was patched. About 600 BTC remained outstanding.

September Overtook April as 2026’s Costliest Month

The September total also breaks the previous annual high.

PeckShield data had placed April losses at approximately $646.9 million, largely because of the Drift and KelpDAO incidents. July followed at roughly $270 million, while August fell to about $136.3 million despite recording 50 major hacks.

September therefore represented more than a fivefold increase from August by dollar value. It also pushed PeckShield’s monthly incident count from 50 to 55, setting another high for the year under that dataset.

CertiK’s figures tell a similar story. Its September estimate of $768.4 million across 97 incidents brought its reported 2026 security losses to approximately $2.68 billion across 656 incidents.

That means September alone represented close to 29% of CertiK’s reported dollar losses for the entire year through the end of the month.

Other notable September incidents were much smaller than Bitget and Liquid. CertiK listed losses involving Safe Wallet at approximately $7.8 million, DCENT at $6 million and Duelbits at $5.9 million.

Those figures illustrate just how distorted September was by its two largest events. Using PeckShield’s $766.5 million total and approximate $388 million and $320 million values for Bitget and Liquid, all other major incidents combined account for only about $58.5 million.

The $766.5 Million Headline Needs an Important Qualification

For investors, there is an important difference between the value involved in an exploit and the value ultimately lost.

PeckShield’s $766.5 million figure captures the scale of funds affected by security incidents. It should not automatically be interpreted as $766.5 million of permanently unrecoverable cryptocurrency.

Liquid is the clearest example. Roughly $320 million was removed from the network, but more than $270 million subsequently came back. The initial exploit still matters because the vulnerability allowed an attacker to withdraw almost the entire Bitcoin reserve, but the final financial damage is much smaller than the gross incident value.

Bitget is different. Stolen assets have continued moving through multiple blockchains and conversion systems. Dave Finances has tracked how the attackers moved thousands of stolen ZEC into Zcash’s Ironwood shielded pool, while other assets have been routed through cross-chain infrastructure and Bitcoin.

That distinction matters when monthly hack statistics are compared. A $300 million exploit followed by a $270 million recovery poses a very different economic outcome from a $300 million theft in which almost nothing comes back, even though both can initially appear as $300 million incidents in a gross-loss table.

Two Incidents Tell More Than the Monthly Average

The September figures also show why average hack losses can be misleading.

Dividing PeckShield’s $766.5 million total by 55 incidents produces an average loss of almost $14 million per event. But the typical September hack was nowhere near that size.

Remove Bitget and Liquid and approximately $58.5 million remains across the other 53 major incidents. That works out to just over $1 million per incident on a simple average basis.

The difference is enormous.

Crypto security risk is therefore not just about how frequently protocols, exchanges or wallets are attacked. A small number of catastrophic failures can dominate an entire year’s loss statistics.

For investors holding assets on centralized exchanges or interacting with blockchain infrastructure, that makes architecture more important than incident frequency alone. A platform can go years without suffering a major loss and still have one hidden weakness capable of overwhelming years of otherwise successful security operations.

September Exposed Two Very Different Types of Crypto Risk

Bitget and Liquid are especially useful to compare because they failed in fundamentally different places.

Bitget’s breach involved centralized operational infrastructure. The attackers appear to have worked through third-party security software, internal credentials and systems responsible for generating and authorizing withdrawals. The incident demonstrates that private keys can remain secure while the systems instructing those keys are compromised.

Liquid’s vulnerability sat deeper in protocol validation. The attacker was able to create L-BTC that should never have existed and then use a legitimate peg-out process to exchange those unbacked assets for real Bitcoin.

One incident was largely an institutional cybersecurity failure. The other was a software-consensus failure.

That diversity is arguably more important than the $766.5 million headline. Crypto security is no longer a single problem that can be solved by better smart-contract audits or moving private keys into cold storage. The attack surface now extends through exchange backends, third-party vendors, employee identities, bridges, sidechains, wallets, transaction-validation software and the infrastructure used to move assets between networks.

Recovery Infrastructure Is Becoming Part of the Security Story

The second half of a crypto hack now matters almost as much as the exploit itself.

Transparent blockchains allow investigators to follow stolen assets in real time, but visibility does not guarantee recovery. Once funds move into privacy systems, decentralized exchanges, bridges or cross-chain swap infrastructure, the ability to intervene depends on how those systems are designed.

The Bitget case has already turned this into a broader debate. NEAR Intents says its screening infrastructure rejected more than $50 million in attempted Bitget-linked flows, while THORChain defended its permissionless architecture when asked to restrict attacker addresses. That has created a wider question over how DeFi protocols should respond when known stolen funds arrive.

For investors, September’s numbers therefore carry two messages.

The first is obvious: crypto remains capable of producing extraordinarily large security losses, and one compromised exchange or protocol can change the statistics for an entire year.

The second is more nuanced. Gross hack totals increasingly tell only the beginning of the story. What gets frozen, returned, insured, absorbed by an exchange, laundered successfully or permanently recovered can materially change the economic impact after the initial exploit.

September was the worst month of 2026 by headline losses. The more useful question now is how much of that $766.5 million ultimately stays lost.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *