Particle.news

September Crypto Hacks Top $768 Million, Driven by Bitget and Liquid Network

The spike signals a shift toward operational and third-party failures that has forced rapid forensic work and partial fund recoveries.

Overview

  • Security trackers put September’s gross losses at roughly $766–$768 million, making it the costliest month of 2026 and concentrated in two incidents that together accounted for more than $700 million.
  • Bitget confirmed that about $387.5 million reached attacker-controlled addresses after a Sept. 24 hot-wallet compromise, and independent forensics by Mandiant and SlowMist tied the breach to compromised third-party security software.
  • Liquid Network was exploited on Sept. 6 when a rangeproof verification cache bug allowed creation of roughly 4,000 unbacked L-BTC; the attacker returned about 3,400 BTC soon after, leaving roughly 602 BTC outstanding while peg-outs remained paused for fixes and audits.
  • Security firms report rising incident counts for 2026 with different tallies by tracker—CertiK shows about 656 incidents and $2.68 billion lost year-to-date while DefiLlama’s late-September snapshot rose toward 277 incidents and about $1.84 billion—reflecting divergent methods but the same worsening trend.
  • The month’s losses expose weak points in key management and third-party tooling, strain limited on-chain insurance capacity, and are prompting bounties, fund-tracing efforts, emergency patches, and greater regulatory and reputational scrutiny that could change how firms manage operational security.