September 2026 closed the books as the most expensive month for crypto theft this year. Attackers pulled more than $766 million out of exchanges, bridges, and DeFi protocols in 30 days, according to tracking compiled by crypto.news. Two incidents, a hot-wallet breach at Bitget and a validation flaw on the Liquid Network, account for most of that total. A dozen smaller exploits filled in the rest, and the pattern hasn’t stopped: on October 2, SlowMist’s security team flagged a fresh compromise of an Aave v3 Loop Safe Module that drained roughly 114 ETH from two multisig wallets.

For an industry that spent the first half of 2026 arguing it had turned a corner on security, the September numbers land hard. This piece breaks down what happened, who got hit, how the losses compare to prior incidents, and what the pattern says about where crypto security is actually heading into 2027.

September 2026 by the numbers: $766 million gone

Crypto.news put the gross September total at more than $766 million, with a separate tally citing $768 million once late-reported incidents were folded in. Either figure makes September the costliest hacking month of 2026, surpassing the monthly totals recorded earlier in the year during the first and second quarters. The bulk of that figure traces to two incidents that happened within days of each other in the back half of the month.

Bitget’s breach, confirmed on September 24, carried an initial estimate of $351.6 million. Investigators later widened that figure to roughly $387.5 million once they finished tracing funds moved to attacker-controlled addresses across Ethereum, other EVM chains, XRP Ledger, Zcash, and Tron. Bitget said the intrusion stemmed from compromised third-party security infrastructure rather than a flaw in its own smart contracts, and that the attacker used forged wallet-withdrawal commands to move assets out of hot and warm wallets.

The Liquid Network exploit unfolded on a different axis entirely. A software-validation bug let the attacker mint roughly 4,000 unbacked L-BTC, assets that were supposed to be fully collateralized by real bitcoin locked in the network’s federation. What makes this one unusual is the ending: the attacker returned approximately 3,400 BTC, or about 85% of the exploited amount, days after the breach became public. That partial reversal is rare in crypto hacks and has fueled speculation about whether the actor was a researcher testing the limit of the flaw, a white-hat under pressure, or someone negotiating a bounty behind the scenes.

Below the headline incidents, a long tail of smaller exploits added up fast.

September 2026 crypto hack ledger

IncidentDateEstimated lossRoot cause
BitgetSept. 24, 2026$351.6M (initial), ~$387.5M (revised)Compromised third-party security infrastructure, forged withdrawal commands
Liquid NetworkMid-to-late Sept. 2026~4,000 unbacked L-BTC minted; ~3,400 BTC (85%) returnedSoftware validation flaw in L-BTC minting logic
Full Sail (Sui)Sept. 2026Protocol shutdown announcedSwitchboard oracle exploit
Chainflip (TRON)Sept. 17, 2026736,442 USDT across 8 attacksMemo-handling bug enabling repeated payouts
Payy NetworkSept. 24, 2026~$1.83MEthereum bridge drain, transactions halted in response
SymbiosisSept. 2026~15 BTC recovered post-exploitBitcoin Bridge exploit, native BTC route suspended
Aave v3 Loop Safe ModuleOct. 2, 2026~114.09 ETHCompromise of two Safe multisig wallets, per SlowMist

Separately, a CryptoSlate-affiliated research preprint found that audited DeFi protocols lost roughly $885 million to attacks that fell completely outside the scope of their original audits, once two outlier incidents from the first half of 2026 were excluded. That figure covers a longer stretch than September alone, but it reinforces the same point: a clean audit report does not cover every way a protocol can be drained months or years after launch, especially when teams bolt new modules onto audited code without a fresh review.

Why hot wallets keep failing at exchange scale

Bitget’s breach fits a pattern that has repeated across exchange hacks for years: the attacker didn’t break the exchange’s own smart contracts, they broke the infrastructure layer that authorizes withdrawals. Forged withdrawal commands suggest the attacker gained enough access, through a compromised vendor or internal tooling, to make the exchange’s systems believe a legitimate signer had approved a transfer. That’s an operational security failure, not a cryptographic one, and it’s largely unaffected by how strong an exchange’s cold storage policy looks on paper.

The multi-chain spread of the stolen funds, Ethereum and other EVM networks, XRP Ledger, Zcash, and Tron, also points to a well-resourced actor. Moving funds cleanly across five different chains in the window before an exchange can freeze or flag transactions takes either a lot of advance planning or automated tooling built specifically for cross-chain extraction. Exchanges have gotten faster at freezing centralized-exchange deposits tied to known hacker addresses, which is likely part of why the Liquid Network attacker chose to return most of the stolen BTC rather than try to launder it.

Liquid Network’s partial return is the outlier, not the norm

An 85% return rate stands out against the typical recovery numbers from crypto hacks, which usually hover in the single digits to low double digits once funds hit mixers or cross-chain bridges built for obfuscation. The Liquid Network case suggests the attacker either lacked an efficient laundering path for L-BTC specifically, wanted to avoid the heat that comes with holding a high-profile stolen sum, or treated the exploit as a demonstration rather than a theft. None of those explanations have been confirmed publicly, and the network’s operators have not disclosed whether a bounty or negotiation preceded the return.

What the incident does confirm is a structural risk in wrapped-asset systems: any mechanism that mints a representation of bitcoin, whether through a federation, a bridge, or a smart contract, is only as trustworthy as its validation logic. When that logic has a flaw, the result isn’t a loss of funds already in the system, it’s the creation of new, fake supply that dilutes everyone holding the wrapped asset until the mint is reversed or burned.

The long tail: small exploits, same root causes

The Chainflip incident on TRON illustrates how a narrow bug can be exploited repeatedly before anyone catches it. A memo-handling flaw let an attacker trigger repeated payouts across eight separate attacks, draining 736,442 USDT before Chainflip moved to reset TRON USDT provider balances to zero. Eight attacks against the same bug means the fix wasn’t applied after the first one, either because the team didn’t detect it in time or didn’t recognize the pattern until the cumulative damage became obvious.

Payy Network’s $1.83 million bridge drain on the same day as the Bitget breach shows how easily these events get buried in the news cycle. A million-plus-dollar bridge exploit would have been a standalone headline in a quieter month; in September 2026, it was a footnote next to a $350 million exchange hack. Symbiosis’s Bitcoin Bridge exploit followed a similar arc: an attack, a partial recovery of about 15 BTC, and a suspended native BTC route while the team worked out compensation for affected liquidity providers.

October opens with another Safe multisig compromise

The pattern didn’t pause for the new month. On October 2, SlowMist’s security team reported that an Aave v3 Loop Safe Module had been compromised, with losses totaling approximately 114.09 ETH spread across two Safe multisig wallets. Safe (formerly Gnosis Safe) multisig wallets are the standard for securing DeFi protocol treasuries and admin functions precisely because they require multiple signers to approve a transaction. A compromise at this layer, rather than at the smart contract logic layer, suggests the attack targeted signer credentials, a compromised front end, or a malicious transaction that looked legitimate to the signers who approved it.

That mirrors a theme from earlier in 2026: attackers increasingly target the humans and infrastructure around a protocol rather than the protocol’s own code. A perfectly audited smart contract doesn’t help if the multisig that controls it gets tricked into signing something it shouldn’t.

How September 2026 compares to earlier incidents

To put the scale of September in context, it helps to line it up against other major 2026 incidents that made headlines on their own.

IncidentTimingAmountCategory
September 2026 total (all incidents)Sept. 2026$766M-$768MMonthly aggregate
BitgetSept. 24, 2026~$387.5M revisedExchange hot-wallet breach
Liquid Network (gross mint, before return)Sept. 2026~4,000 unbacked L-BTCBridge/federation validation flaw
Audited-protocol losses outside audit scopeH1-H2 2026 (ex-outliers)$885MDeFi protocol exploits, multi-month
Single-day DeFi cluster (three exploits)Late Sept. 2026$11MDeFi smart contract exploits

The $885 million audit-scope figure is the one worth sitting with. It’s not a single incident, it’s a running tally showing that security audits, while still necessary, are not sufficient protection on their own. A protocol that passed its audit in January can still get drained in September if it adds new functionality, changes its oracle integration, or connects to a bridge that wasn’t part of the original review. Treating an audit as a one-time certification rather than an ongoing process is, by this data, one of the more persistent mistakes in the industry.

Market impact: prices barely moved, confidence did

Despite the scale of the losses, broader crypto market pricing held up through the month. The global crypto market cap stood around $2.72 trillion in mid-September and climbed to roughly $2.99 trillion by October 2, with Bitcoin and Ethereum both trading higher and the Fear and Greed Index reading 72, firmly in “greed” territory. Stablecoin market capitalization also kept climbing, reaching $290.4 billion in mid-September.

That disconnect, record hack losses alongside record market caps, says something about where capital flows in crypto today. Institutional and retail money chasing Bitcoin and Ethereum exposure isn’t primarily routed through the DeFi protocols and smaller exchanges getting hit. The damage lands hardest on the users of the specific platform breached: Bitget customers waiting on fund recovery, Liquid Network participants whose L-BTC was briefly diluted, Chainflip’s TRON liquidity providers. The macro market shrugs because the bulk of trading volume and price discovery happens elsewhere.

That doesn’t mean there’s no cost. Exchanges that suffer a breach face withdrawal suspensions, reputational damage, and regulatory scrutiny that can take months to resolve, even when customer funds are eventually made whole. Bitget temporarily suspended withdrawals following its breach, a standard but costly move that locks up customer liquidity precisely when trust is most fragile.

Competitive pressure: exchanges are racing to out-secure each other

September’s hack wave is reshaping how exchanges compete, not just on fees and listings but on visible proof of security posture. Exchanges that can point to clean incident histories, published proof-of-reserves, and fast post-breach transparency are starting to use that as a marketing differentiator against rivals still working through the fallout of a hack. CoinEx, separately, announced it will wind down entirely after nine years, ending spot trading on September 29 and withdrawals by December 22, citing lower liquidity and rising compliance costs rather than a hack. That closure, happening in the same month as the Bitget and Liquid incidents, adds to a sense that mid-tier exchanges face a tightening margin between security costs, compliance costs, and the fees they can realistically charge.

For DeFi protocols, the competitive pressure is different: a growing number of institutional partners and integrators are starting to ask not just whether a protocol has been audited but how many audits, by which firms, covering which version of the code, and how recently. Protocols that can answer with a continuous audit trail, rather than a single report from launch day, have an edge in attracting the kind of treasury and institutional liquidity that doesn’t want to be the next line item in a monthly hack ledger.

Historical context: 2026’s hack trajectory

Crypto hacking losses have followed a jagged but generally upward path for most of 2026. Early in the year, headline incidents tended to be concentrated in a handful of very large bridge and exchange exploits, with quieter stretches in between. September broke that rhythm by combining one mega-incident (Bitget) with a cluster of mid-size and small exploits happening almost simultaneously, suggesting attackers are either coordinating opportunistically around periods of lower vigilance or simply that the sheer number of live DeFi protocols and bridges has grown to the point where some exploit is nearly always in progress somewhere.

The $885 million in out-of-audit-scope losses tracked across the year also marks a shift in how the industry talks about security failures. Earlier years saw post-mortems focus heavily on whether a protocol had been audited at all. The 2026 conversation has moved to a more uncomfortable question: audits are now common, but they’re being outpaced by how fast protocols ship new features, integrate new oracles, and bolt on new bridges after the audit is complete.

What exchanges and protocols are changing in response

In the days following the Bitget breach, the exchange suspended withdrawals across affected wallet infrastructure while it traced the forged-command exploit path, a standard containment step. Liquid Network’s federation had to work through how to formally reverse or burn the unbacked L-BTC that wasn’t returned by the attacker, to avoid leaving a permanent supply overhang. Chainflip’s decision to reset TRON USDT provider balances to zero after the memo-handling exploit is a more drastic step: it effectively asks liquidity providers to accept a loss-absorption event rather than waiting for a slower recovery process.

Across the incidents, a common thread is emerging: teams are increasingly choosing fast, decisive, and sometimes painful remediation (balance resets, withdrawal freezes, route suspensions) over slower investigations that leave user funds in limbo. That’s a meaningful shift from the earlier-2026 pattern where some protocols took weeks to even confirm whether an exploit had occurred.

Predictions for the rest of 2026 and into 2027

  • Monthly hack totals will likely stay elevated through Q4 2026, given the pace of new DeFi protocols and bridges launching without proportional increases in post-launch audit coverage.
  • Expect more exchanges to publish real-time proof-of-reserves and incident-response transparency reports as a competitive differentiator, following the reputational hit Bitget took in September.
  • Multisig and Safe-wallet-targeted attacks, like the October 2 Aave v3 incident, will likely increase as attackers shift focus from smart contract bugs (which are getting harder to find in heavily audited code) to the human and operational layer around treasury management.
  • Wrapped-asset systems like Liquid Network will face pressure to adopt more conservative minting validation, even at the cost of slower settlement, after the unbacked L-BTC incident exposed how quickly a validation flaw can create phantom supply.
  • Continuous or subscription-based audit models, where firms monitor a protocol’s code on an ongoing basis rather than issuing a single point-in-time report, are likely to gain adoption given the $885 million in losses tied to out-of-scope changes made after initial audits.

What this means for everyday crypto users

None of these incidents targeted individual wallet holders directly, but the ripple effects reach them anyway. Users with funds on an exchange during a breach face withdrawal freezes that can last days or weeks. Liquidity providers on an exploited bridge or protocol absorb losses through balance resets or diluted pool shares. And the broader erosion of trust in any single platform pushes more users toward self-custody, even though self-custody carries its own operational risks if private keys and seed phrases aren’t managed carefully.

The practical takeaway for anyone holding meaningful crypto balances: diversify custody rather than concentrating funds on a single exchange or protocol, watch for official communications directly from a platform rather than social media rumors during an active incident, and treat “audited” as a starting point for due diligence rather than a guarantee.

Frequently asked questions

How much was stolen in crypto hacks during September 2026?
Tracking from crypto.news puts the gross total above $766 million, with some tallies citing $768 million once late-reported incidents were included, making it the costliest hacking month of 2026.

What caused the Bitget hack?
Bitget said the breach stemmed from compromised third-party security infrastructure, with the attacker using forged wallet-withdrawal commands to move funds across Ethereum and other EVM networks, XRP Ledger, Zcash, and Tron.

Did Liquid Network get its funds back?
The attacker returned approximately 3,400 BTC, roughly 85% of the roughly 4,000 unbacked L-BTC created through the exploited validation flaw.

What was the Aave v3 Safe Module incident on October 2?
SlowMist’s security team reported a compromise of an Aave v3 Loop Safe Module that resulted in a loss of approximately 114.09 ETH across two Safe multisig wallets.

Are audited DeFi protocols still at risk of being hacked?
Yes. Research cited by CryptoSlate found audited protocols lost approximately $885 million to attacks that occurred entirely outside the scope of their original audits, often after the protocol shipped new features or integrations post-audit.

Did the hacks affect Bitcoin or Ethereum prices?
Not materially at the macro level. The global crypto market cap rose from about $2.72 trillion in mid-September to roughly $2.99 trillion by October 2, with Bitcoin and Ethereum both trading higher despite the hack wave.

What is a Safe multisig wallet, and why do attackers target it?
Safe (formerly Gnosis Safe) multisig wallets require multiple approvals before a transaction executes, and they’re widely used to secure DeFi protocol treasuries. Attackers target them because compromising signer credentials or tricking signers into approving a malicious transaction can bypass even well-audited smart contract code.

What should crypto users do after a wave of hacks like this?
Spread holdings across multiple custody solutions rather than one exchange, verify incident updates only through official channels, and treat a protocol’s audit history as one input among several rather than a guarantee of safety.