
Crypto Hack Losses Reach $1.26 Billion in Q3 2026
CoinDesk, citing CertiK, puts third-quarter theft at about $1.26 billion across 247 incidents. Two September events, at Bitget and Liquid Network, account for most of that month's losses, though full post-mortems are not yet public.
CoinDesk, citing CertiK, reports about $1.26 billion lost to crypto hacks across 247 incidents in the third quarter of 2026, with September the heaviest month. Two incidents, Bitget and Liquid Network, account for most of September's loss, according to crypto.news. Causes are reported, not yet confirmed by full post-mortems.
The Ledger Desk · 4 min read- CoinDesk, citing CertiK, reports $1.26 billion lost across 247 incidents in Q3 2026, and $2.68 billion year to date.
- Crypto.news reports that Bitget (about $387.5 million, Sept. 24) and Liquid Network (about $319 million, Sept. 6) together make up roughly 92% of CertiK's September total of $768.4 million.
- Both outlets cite CertiK for September but differ slightly: CoinDesk gives $768.5 million across 99 incidents, crypto.news gives $768.4 million across 97. Neither explains the gap.
- Tracker incident counts are not interchangeable: PeckShield counted 55 September incidents against CertiK's 97, with near-identical dollar totals.
- The reported causes are a compromised third-party security tool and a verification-cache error. Treat them as unconfirmed until the firms publish post-mortems.
Crypto lost about $1.26 billion to hacks in the third quarter of 2026 across 247 incidents, according to CertiK data reported by CoinDesk on October 1. CoinDesk puts the year-to-date total at $2.68 billion. The headline pairs those losses with a strong quarter for bitcoin, and the contrast is the point: the money is leaving through operational plumbing, not through price moves. All figures below are as reported by CoinDesk and crypto.news, not independently verified.
September's totals agree in dollars, not in counts
CoinDesk reports that CertiK recorded about $768.5 million stolen across 99 incidents in September, while crypto.news reports CertiK at $768.4 million across 97. Neither outlet explains the small gap. Crypto.news also reports PeckShield at $766.49 million across 55 incidents. Dollar totals across the two firms sit within about $2 million of each other, but incident counts diverge sharply, so trend comparisons should stay within a single tracker's methodology.
Two incidents account for most of the month
Crypto.news reports that Bitget lost about $387.5 million on Sept. 24 and Liquid Network about $319 million on Sept. 6. Together that is roughly $706 million, about 92% of CertiK's September figure. The remainder is a long tail, including Safe Wallet at $7.8 million, DCENT at about $6 million and Duelbits at $5.9 million. A quarterly headline number is therefore set by a handful of events rather than broad attrition.
Reported causes point to vendor and verification layers
Crypto.news quotes the Bitget account as compromised third-party security software giving an attacker unauthorized access to its wallet environment, including hot and warm wallets across several networks. It quotes the Liquid Network cause as an error in its rangeproof verification cache that let a malicious transaction pass validation. These are reported descriptions, not confirmed post-mortems, and should be treated as provisional until the affected firms publish their own findings.
Partial recovery does not settle the reputational question
Crypto.news reports that 3,400 BTC tied to the Liquid Network incident were returned on Sept. 7, with about 602 BTC outstanding. CoinDesk quotes Nansen senior research analyst Nicolai Sondergaard as saying the episode is bad optics and that repeated exploits reinforce the idea that crypto infrastructure remains operationally fragile. That is an analyst's opinion, not a measured outcome, and CoinDesk also quotes Tesseract Group's Oliver Carding on AI tools speeding up the search for smart-contract weaknesses.
What this means for operators and allocators
For firms holding customer assets or exposure to exchanges and bridges, the practical read is to map third-party dependencies in the wallet-security and signing path, and to ask how hot and warm wallet limits are enforced. On the verification side, ask whether cache or validation logic has independent review. Watch for the firms' own post-mortems and for any regulator citing these incidents in custody or operational-resilience requirements.
- How much did crypto lose to hacks in Q3 2026?
- CoinDesk, citing CertiK, reports about $1.26 billion lost across 247 security incidents in the third quarter. CertiK's year-to-date figure, as reported by crypto.news, is $2.68 billion across 656 incidents.
- What drove the September losses?
- Crypto.news reports two large incidents: Bitget on Sept. 24 (about $387.5 million) and Liquid Network on Sept. 6 (about $319 million). Smaller losses included Safe Wallet at $7.8 million, DCENT at about $6 million and Duelbits at $5.9 million.
- Why do September incident counts differ between origins?
- Crypto.news reports PeckShield at $766.49 million across 55 incidents and CertiK at $768.4 million across 97. CoinDesk gives CertiK as $768.5 million across 99. The dollar totals are close, but incident counts depend on each tracker's definitions, and the CertiK discrepancy between outlets is unexplained.