CertiK recorded the highest monthly loss total and incident count for 2026 in September, with confirmed damages reaching $766.4 million. Two significant breaches accounted for over 92% of this figure: a $387.5 million theft from centralized exchange Bitget on September 24 and a $318.7 million exploit of Blockstream’s Liquid Network on September 6. While CertiK classified about $270.6 million as returned or frozen, the residual losses exceeded August’s entire gross tally.
The Bitget incident involved unauthorized transfers from hot wallets, which CEO Gracy Chen attributed to a vulnerability in a third-party security product that allowed attackers to inject fraudulent withdrawal commands. Interim forensic findings from SlowMist and Mandiant indicated the attacker gained access via a zero-day flaw weeks prior. Meanwhile, the Liquid Network exploit stemmed from a caching flaw in range proof verifications, allowing unbacked issuance of L-BTC. Although a white-hat team returned 3,400 BTC, approximately 602 BTC remained retained, leading Blockstream to treat the remainder as theft.
This surge in losses highlights a critical shift in the attack surface for digital asset infrastructure, moving away from traditional smart contract reentrancy bugs toward vulnerabilities in operational controls and third-party dependencies. The Bitget breach demonstrates how supply chain risks within wallet management systems can compromise even established exchanges, while the Liquid Network incident underscores the fragility of federated sidechains where cryptographic validation logic errors can lead to massive value leakage. These events suggest that current security audits may be insufficient if they do not rigorously test integration points between core protocols and external service providers.
For institutional participants, the reliance on User Protection Funds and emergency patches introduces new layers of counterparty risk. Bitget’s ability to restore its protection fund to $309 million mitigates immediate solvency concerns, but the prolonged downtime and phased reopening of withdrawals indicate that recovery timelines remain unpredictable. Market structure implications are also evident in the response mechanisms; THORChain’s refusal to block attacker addresses due to permissionless design principles contrasts sharply with the centralized interventions seen in other cases. Stakeholders should monitor whether regulatory frameworks evolve to mandate stricter vendor due diligence and real-time threat intelligence sharing across decentralized networks.


