CertiK recorded the highest monthly loss total and incident count for 2026 in September, with confirmed damages reaching $766.4 million. Two significant breaches accounted for over 92% of this figure: a $387.5 million theft from centralized exchange Bitget on September 24 and a $318.7 million exploit of Blockstream’s Liquid Network on September 6. While CertiK classified about $270.6 million as returned or frozen, the residual losses exceeded August’s entire gross tally.

The Bitget incident involved unauthorized transfers from hot wallets, which CEO Gracy Chen attributed to a vulnerability in a third-party security product that allowed attackers to inject fraudulent withdrawal commands. Interim forensic findings from SlowMist and Mandiant indicated the attacker gained access via a zero-day flaw weeks prior. Meanwhile, the Liquid Network exploit stemmed from a caching flaw in range proof verifications, allowing unbacked issuance of L-BTC. Although a white-hat team returned 3,400 BTC, approximately 602 BTC remained retained, leading Blockstream to treat the remainder as theft.