September marked the worst month for crypto hacks in 2026, with losses exceeding $766 million according to estimates from blockchain security firms PeckShield and CertiK. PeckShield recorded 55 major incidents totaling $766.5 million in stolen funds, while CertiK tracked 97 incidents with estimated losses of $768.4 million. Both figures represent a significant increase compared to August.
The month’s losses were dominated by two large-scale attacks: a $388 million hack at Bitget and a $320 million exploit targeting the Liquid Network. Reports indicate that more than $270 million was subsequently returned. Other notable incidents included breaches at Safe Wallet, DCENT, and Duelbits, which lost $7.8 million, $6 million, and $5.9 million respectively. CertiK’s dashboard shows that 2026 has seen 656 security incidents year-to-date, accumulating total losses of $2.68 billion.
The concentration of capital loss in just two incidents highlights the persistent vulnerability of centralized exchange infrastructure and cross-chain bridges to sophisticated exploits. The return of over $270 million suggests that rapid incident response and potential law enforcement cooperation can mitigate final damages, yet the sheer scale of the initial theft underscores the high stakes involved in custody management. This disparity between stolen and recovered funds remains a critical metric for assessing the effectiveness of current security protocols against state-level or highly organized criminal groups.
Institutional adoption faces renewed scrutiny as the cumulative 2026 losses approach $2.68 billion, indicating that despite advancements in smart contract auditing, operational security gaps remain prevalent. The divergence in incident counts between PeckShield and CertiK reflects differing methodologies in defining "major" incidents, complicating standardized risk assessment for investors. Future regulatory frameworks may need to mandate stricter real-time monitoring and insurance requirements for exchanges handling such volumes, particularly given the recurring nature of zero-day exploits traced back to late August.


