Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Bitget, Liquid Hacks Drive Crypto Losses to $766M in September, 2026’s Worst Month: CertiK

Two major exploits accounted for over 92% of September’s damage, while CertiK recorded the year’s highest number of security incidents.

Written By Dishita Malvania
Edited by Divya Mistry
Published 2026-09-30·Updated 2 days ago
Make The Crypto Times preferred on GoogleGoogle
Bitget, Liquid Hacks Drive Crypto Losses to $766M in September, 2026's Worst Month: CertiK

Crypto platforms and users lost approximately $766.4 million to exploits and phishing in September 2026, the highest monthly total and the highest incident count recorded this year, blockchain security firm CertiK said on Wednesday, September 30. 

Two incidents, the $387.5 million theft from cryptocurrency exchange Bitget on September 24 and the $318.7 million exploit of Blockstream’s Liquid Network on September 6, made up more than 92% of the month’s confirmed losses. CertiK classified about $270.6 million of the total as returned or frozen.

AI Summary
Show
September 2026 saw $766 million crypto losses, a 3.5× increase over August’s $215 million.
Bitget’s $387.5 million theft alone wiped out over half the month’s total losses.
Returned or frozen assets total $270.6 million, leaving roughly $496 million unrecovered net loss.

CertiK’s September 2026 Loss Breakdown

CertiK is a blockchain security firm that audits smart contracts and tracks Web3 security incidents. Its incident-tracking account, CertiK Alert, published the September figures on X at 12:00 Coordinated Universal Time (UTC) on September 30. The accompanying statistics graphic put the exact total at $766,451,111 and listed $270,610,532 as returned or frozen.

CertiK Report’s dashboard about total losses in September 2026
CertiK Report’s dashboard about total losses in September 2026, Source: CertiK Report

The firm’s Security Report Dashboard, which aggregates incident data by quarter, had not yet refreshed its September widgets at the time of writing. The X graphic is therefore the operative source for the month-end figure.

Top Five Incidents in September 2026

RankIncidentDateLoss (USD)
1BitgetSeptember 24$387,500,000
2Liquid NetworkSeptember 6$318,667,698
3Safe Wallet UsersMid-September$7,800,000
4D’CENTSeptember 15 to 20$6,029,452
5DuelbitsSeptember 24$5,972,343

The same graphic listed further incidents: ShopLink at $4.7 million, Astroport at $4.4 million, an unknown victim at $4.3 million, Nostra Finance at $3.5 million and unknown wallets at $2.8 million.

Losses by Category

CertiK groups incidents by the type of platform affected. A centralized exchange (CEX) is a company-run trading venue that holds customer funds. Mainnet refers to a live base-layer or sidechain network, and decentralized finance (DeFi) covers protocols that run on smart contracts without an intermediary.

CategoryLoss (USD)
CEX$387,500,000
Mainnet$325,109,026
Individual$18,548,452
DeFi$13,298,693
Gambling$5,987,763

The five categories shown in the graphic total about $750.4 million, so they do not account for every dollar of the monthly figure.

Losses by Attack Type

TypeLoss (USD)
Third Party Service$387,500,000
Invalid Signature$324,697,151
Wallet Compromise$20,103,839
Improper Permission Control$13,298,693
Reentrancy$2,248,138

Reentrancy is a smart contract flaw in which an external call re-enters a function before its balances update, and it has historically been the signature DeFi bug. It accounted for only about $2.25 million in September. The month’s damage came instead from third-party infrastructure, flawed signature and proof validation, wallet compromise, and permission control.

How September Compares With August and the First Half of 2026

September’s total did not climb through a series of mid-size DeFi bugs. It jumped because two outsized failures landed in the same 30-day window.

CertiK’s August 31 recap put August 2026 losses at about $215 million, with the $120.4 million Tectonic price-manipulation incident as the largest item and $110.7 million later marked as returned or frozen. September’s gross figure is more than 3.5 times that total. Even after subtracting the $270.6 million returned or frozen, September’s residual of about $495.8 million exceeds August’s entire gross tally.

The first half of the year had already set a high baseline. CertiK’s Hack3D H1 2026 report counted $1,315,676,432 lost across 344 incidents between January and June. That headline was 46.8% below the first half of 2025 only because 2025 included the roughly $1.45 billion Bybit hack in February 2025. Excluding Bybit, CertiK said H1 2026 losses were about 28% higher on a comparable basis.

The same report named wallet compromise as the costliest attack vector of the half, at $444,531,691 across 33 incidents. September extended that pattern, with operational controls, third-party products, signing flaws, and governance votes causing more damage than classic smart contract bugs.

Bitget Hack: $387.5 Million Through a Third-Party Security Product

Bitget is a Seychelles-registered centralized cryptocurrency exchange. According to its security notice, its systems detected unauthorized transfers from some hot wallets at 18:31 UTC on September 24, 2026. Hot wallets stay connected to the internet to process routine withdrawals, while warm wallets sit between hot and offline cold storage. Bitget said cold wallets and its separate Bitget Wallet product were not affected, and that private keys were not stolen.

How the Theft Unfolded

Bitget’s first public estimate was $351.6 million. On September 25, the exchange raised the figure to about $387.5 million after adding Zcash (ZEC) and TRON (TRX) transfers from the original attack window, a revision that did not reflect a second breach.

XRP was the largest single asset taken, at roughly 103 million tokens worth about $157 million in early tallies. Other affected assets included Ether (ETH), Tether (USDT), USD Coin (USDC), USDT0, Tether Gold (XAUt), ZEC, BNB, Avalanche (AVAX) and TRX. The transfers ran across Ethereum, the XRP Ledger, TRON, BNB Chain, Base, Arbitrum, Optimism and Avalanche.

Blockchain security firm GoPlus Security later reconstructed the cash-out sequence:

  • 18:31 UTC: an attacker-controlled address was funded with 0.84 ETH and 93 TRX to pay network fees.
  • 18:58 UTC: the first large stablecoin transfer, worth about $34.75 million, moved.
  • 19:16 UTC: a one-minute wave moved about $185 million, including 13,966 ETH, about 91.4 million XRP, and 20.6 million TRX.
  • 21:23 UTC: on-chain theft ended after a window of roughly two hours and 52 minutes.

Forensic Findings From SlowMist and Mandiant

On September 28, Bitget Chief Executive Officer (CEO) Gracy Chen said the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials. The attacker then injected fraudulent withdrawal commands into the wallet backend.

Interim forensic findings released on September 30 by SlowMist and Mandiant pushed the timeline further back. SlowMist, a blockchain security firm, dated the earliest logged malicious activity to August 31. It said a zero-day vulnerability, a software flaw unknown to the vendor with no available fix, gave the attacker a foothold in a third-party security product weeks before any funds moved.

Mandiant, Google Cloud’s incident response and threat intelligence unit, said the actor deployed a web shell, moved laterally to a production wallet job server and used a custom withdrawal tool built around Bitget’s own withdrawal logic. Neither firm named the affected vendors, which SlowMist labelled Product A and Product B, and both described their findings as interim.

Protection Fund and Withdrawal Restart

Bitget said customer balances were not written down and that its User Protection Fund, a reserve it set up in 2022 with a $300 million commitment, would absorb the loss. The fund held more than $464 million when the exchange disclosed the breach. Covering the shortfall later pushed it below $200 million, Bloomberg reported.

On September 30, Bitget said it had restored the fund to $309 million, including 3,705 BTC, meeting its pledge to bring it back above $300 million.

The exchange paused withdrawals while keeping deposits and trading open. Its phased withdrawal schedule reopened BTC at 08:00 UTC on September 28, ETH on September 29, and USDT on September 30, each at 08:00 UTC. Other tokens, fiat and peer-to-peer (P2P) services are scheduled for 08:00 UTC on October 2. When ETH withdrawals reopened, Bitget reported a first-hour net inflow of 651 ETH, about $1.2 million.

Laundering and Attribution

Laundering continued through the week. THORChain, a cross-chain swap protocol, declined Chen’s request to block attacker addresses, citing its permissionless design. NEAR Intents said attackers tried to route more than $50 million through its rails. Only about $669,000 reached the system, of which $503,000 was frozen mid-swap and $166,000 completed.

On-chain investigator ZachXBT on September 28 published the identities of five alleged launderers he linked to suspected North Korean operators. On September 30, he said about 2,700 ZEC, worth roughly $3.8 million, had entered Zcash’s Ironwood shielded pool, which hides transaction details using zero-knowledge proofs.

Bitget has pointed to virtual private network (VPN) and on-chain patterns consistent with the Democratic People’s Republic of Korea (DPRK). It has also published attacker addresses alongside a fund tracing and recovery bounty program. No state has formally attributed the attack.

Liquid Network Exploit: $318.7 Million in Unbacked L-BTC

Liquid Network is a federated Bitcoin sidechain built by Blockstream on Elements, an open-source blockchain platform. Its Liquid Bitcoin (L-BTC) token is meant to be backed one-to-one by BTC held in a reserve controlled by the Liquid Federation, a group of member organizations that run the network’s signing nodes.

How the Bug Worked

According to Liquid’s September 8 incident report, the exploit stemmed from a vulnerability in how Liquid nodes cache range proof verifications and was triggered in Liquid block 4,050,336. A range proof is a cryptographic check that a hidden transaction amount falls within a valid range. The caching flaw let a transaction pass validation even though its output value was not backed by its inputs.

SlowMist later put the unbacked issuance at about 3,998.5 L-BTC. SideSwap, a federation member that holds a Peg-out Authorization Key (PAK), then processed a standard peg-out, the step that burns L-BTC and releases BTC on the Bitcoin main chain. The PAK itself was not compromised. The federation paid out about 3,996 BTC in Bitcoin block 965,783.

Other Liquid-issued assets, including USDT, DePix and tokenized real-world assets (RWAs), were not drained, though they were frozen while the network was paused.

3,400 BTC Returned, About 600 BTC Still Outstanding

The actor identified itself on-chain as a white-hat team, meaning ethical hackers, and demanded a patch before returning funds. Blockstream’s incident assessment says the actor returned 3,400 BTC at 16:09 UTC on September 7, in Bitcoin block 965,950. Blockstream deployed an emergency interim patch within hours and released the reviewed fix, Elements v23.3.4, on September 9.

Liquid’s September 8 report put the retained amount at about 598.5 BTC, while Blockstream’s later assessment puts it at about 602 BTC. The retained coins were worth roughly $47 million at the time of the return.

Blockstream CEO Adam Back rejected a 10% bounty demand and said Blockstream would cover the L-BTC peg shortfall. Blockstream’s assessment treats unauthorized retention of the remainder as theft, not agreed white-hat compensation. Liquid said on September 28 that an external audit of Elements v23.3.4 is underway before peg-outs are restored.

CertiK’s graphic values the Liquid incident at $318,667,698, close to the $319 million to $320 million figures used in first-week coverage. The 3,400 BTC return is the main reason CertiK can show $270.6 million returned or frozen for the month.

Other Incidents in CertiK’s September Tally

The remaining incidents were far smaller than Bitget and Liquid, but their number explains why CertiK recorded September as 2026’s busiest month.

Safe Wallet Users: $7.8 Million

A Safe wallet, a smart contract wallet that can require several approvals per transaction, lost about $7.8 million in restaked Ether (rsETH) in mid-September. CertiK listed the event as “Safe Wallet Users,” the month’s third-largest exploit. The drain led to a week of about $20 million in confirmed losses that also included Nostra Finance.

D’CENT: $6.03 Million in CertiK’s Table

D’CENT, a South Korean wallet provider, said the exposure sat in its App Wallet, not its hardware devices, and pointed to app versions before 8.1.0. The first customer reports arrived in South Korea on September 16.

XRP Ledger (XRPL) tracing later counted six waves between September 15 and September 20 that emptied 6,678 wallets of about 11.7 million XRP. Further theft after September 21 pushed the tally above 12.4 million XRP across more than 7,000 wallets. 

CertiK’s $6.03 million figure appears to reflect an earlier valuation window. D’CENT told affected users to generate a new recovery phrase and move their assets.

Duelbits: $5.97 Million

Hot wallets belonging to crypto casino Duelbits on Ethereum, BNB Chain, TRON, Solana and Bitcoin were emptied between 08:58 and 09:56 UTC on September 24, the same day as the Bitget theft. The outflows were consolidated into about 2,235 ETH. 

Duelbits co-founder Joe put the loss near $7 million, took the site offline, and said user funds were safe. Security firms treated the incident as a suspected private-key compromise.

Astroport: $4.4 Million

On September 22, Neutron governance proposal 9 transferred admin rights over Astroport and Drop contracts. Astroport is a decentralized exchange, and Neutron is a smart contract chain in the Cosmos ecosystem. Astroport’s September 29 post-mortem said no Astroport contract bug was exploited.

A linked wallet spent about 20,199 USDC on 31.6 million NTRN, Neutron’s governance token, 11 minutes before voting closed and supplied most of the YES vote. Independent tallies put combined Astroport and Drop damage near $9 million. Cosmos Hub validators later halted the Hub and moved stolen ATOM into a multisig wallet pending a governance vote on its return.

Nostra Finance: $3.5 Million

At 13:28 UTC on September 17, Nostra halted its money market on Starknet, an Ethereum layer-2 network, after a manipulated NSTR oracle price let one account borrow about $3.5 million. 

An oracle is a service that feeds external price data to smart contracts. Blockchain security firm PeckShield tracked about $1.92 million bridged to Ethereum, and CertiK placed about $1.55 million still on Starknet.

ShopLink and Unnamed Victims

ShopLink ($4.7 million), an unknown victim ($4.3 million), and unknown wallets ($2.8 million) remain CertiK line items without public post-mortems. They sit inside CertiK’s individual and wallet-compromise buckets.

What the $766.4 Million Figure Does and Does Not Mean

CertiK’s total is best read as confirmed value moved or created through exploits and phishing in September, not as $766.4 million in permanent customer losses. Gross loss and economic loss differ for each major incident.

Liquid’s $318.7 million gross drain shrinks sharply after the 3,400 BTC return, and Blockstream has pledged to cover the peg shortfall. Bitget’s $387.5 million is a real reserve hit, but the exchange says customers are being made whole from its protection fund rather than through a haircut. D’CENT’s losses sit with individual App Wallet users, while Nostra and Astroport are protocol-level events with mixed recovery paths.

CertiK’s $270.6 million returned-or-frozen figure is the firm’s own adjustment layer. It does not itemize how much comes from Liquid’s 3,400 BTC and how much from smaller freezes, such as the $503,000 halted by NEAR Intents.

What Remains Unresolved

Several questions remained open as of September 30:

  • Bitget has not named the third-party security products SlowMist labelled Product A and Product B, and the SlowMist and Mandiant findings are interim.
  • North Korean involvement in the Bitget theft is alleged but not formally attributed by any state.
  • Remaining Bitget withdrawals, including other tokens, fiat, and P2P services, are scheduled for October 2.
  • About 600 BTC from the Liquid exploit is still outstanding, and Liquid peg-outs await the external audit of Elements v23.3.4.
  • CertiK has not published a full September incident table with timestamps for every event below the top five.
  • D’CENT’s traced XRP losses have outgrown CertiK’s $6.03 million snapshot, so the monthly total may be revised.

Also Read: Bitcoin Price Holds the Low $80,000s as October’s “Uptober” Test Begins

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BitGetCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Aave Labs and MiCA regulation logos with a MiCA Review Consultation document under European Commission oversight
Aave Urges EU to Rethink MiCA Rules for DeFi and Stablecoins
White Bitget exchange logo overlaying a dark mountain peak background
Bitget Alliance Program Reward Pool Tops $1.9M in Three Days After $387.5M Hack
Glowing Aave logo with digital glitch effect set against a dark purple background
Aave v3 Loop Module Hacked for 114 ETH; Aave’s Pools Not Affected
International Monetary Fund IMF signage displayed on a blue wall in multiple languages
IMF Waives El Salvador’s Bitcoin Breach, Approves $138M Disbursement
Gold Bitcoin BTC coin standing upright with autumn leaves and a fluctuating crypto trading chart background
Bitcoin’s Q4 Open: Price Recovery Structure Holds, Breakout Above $87,400 Still Missing

Find Us on Socials

You may also like

NEAR Intents GM Says $3.8M Exploiter Identified, Sets 48-Hour Return Deadline

NEAR Intents GM Says $3.8M Exploiter Identified, Sets 48-Hour Return Deadline

Galaxy and Polymarket corporate logos displayed side by side on dark and blue metallic plaques.

Galaxy Finds 69% of Polymarket Retail Accounts Lost Money

Ripple corporate sign displayed with the flag of Uganda in the background.

Ripple Launches RLUSD Insurance Pilot for Ugandan Farmers

Conceptual representation of an Ethereum crypto transfer between two digital wallets with a hooded hacker and Aave v3 screen in the background.

FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information