Overview
- Security trackers put September’s gross losses at roughly $766–$768 million, making it the costliest month of 2026 and concentrated in two incidents that together accounted for more than $700 million.
- Bitget confirmed that about $387.5 million reached attacker-controlled addresses after a Sept. 24 hot-wallet compromise, and independent forensics by Mandiant and SlowMist tied the breach to compromised third-party security software.
- Liquid Network was exploited on Sept. 6 when a rangeproof verification cache bug allowed creation of roughly 4,000 unbacked L-BTC; the attacker returned about 3,400 BTC soon after, leaving roughly 602 BTC outstanding while peg-outs remained paused for fixes and audits.
- Security firms report rising incident counts for 2026 with different tallies by tracker—CertiK shows about 656 incidents and $2.68 billion lost year-to-date while DefiLlama’s late-September snapshot rose toward 277 incidents and about $1.84 billion—reflecting divergent methods but the same worsening trend.
- The month’s losses expose weak points in key management and third-party tooling, strain limited on-chain insurance capacity, and are prompting bounties, fund-tracing efforts, emergency patches, and greater regulatory and reputational scrutiny that could change how firms manage operational security.