Crypto hacks caused an estimated $766.49 million in losses across 55 major incidents in September, according to blockchain security firm PeckShield. The monthly total was about 462% higher than August’s $136.3 million, but the jump was overwhelmingly concentrated in two large breaches.

PeckShield said the Bitget exploit and the Liquid Network theft together accounted for nearly all of September’s losses. Excluding those two cases, the remaining 53 incidents added up to about $59 million, less than half of August’s total.

Two incidents dominated the month

PeckShield identified the Bitget case, at about $387 million, as the largest crypto theft of the year so far, followed by the roughly $320 million taken from Liquid Network. In the Liquid case, about $285 million was later returned, but the incident still ranked among the year’s biggest losses.

Those two breaches moved ahead of the earlier Drift and KelpDAO/LayerZero exploits in PeckShield’s year-to-date ranking. The concentration of losses in just two events sharply distorted the monthly picture, turning what would otherwise have been a much smaller month into one of the largest for 2026.

Bitget said hot wallets were affected, not cold storage

Bitget previously said its security systems detected unauthorized transfers from parts of its hot wallet infrastructure at 18:31 UTC on September 24. According to CEO Gracy Chen, the attacker accessed a backend system tied to the wallet setup, spoofed transaction data, and bypassed the authorization process to release funds.

Chen said the breach did not involve a private key compromise and that the exchange’s cold wallets, where most customer assets are held, were not affected. Bitget has said it plans to absorb the loss through its User Protection Fund, which it said holds more than $464 million. Chen also stated publicly that the exchange would account for the full amount lost.

Liquid theft was described as a white-hat operation, but doubts remain

The Liquid Network incident took place on September 6, when purported white-hat hackers withdrew around 4,000 BTC from the Liquid Federation wallet. Liquid said the withdrawal relied on the SideSwap peg-out authorization key, while adding that the key itself had not been compromised.

In messages posted on-chain to Blockstream, the party behind the withdrawal said the funds would be returned after every node had been patched. That explanation did not convince everyone. Ledger CTO Charles Guillemet said legitimate security researchers would not normally drain a bridge first and then seek contact through on-chain messages.

Investigators tracked laundering activity and several smaller exploits

In a September 29 update, SlowMist said North Korea-linked hackers were laundering the stolen Bitget funds by pairing CoW Protocol orders with Chainflip deposit addresses, converting the assets into BTC and then using CoinJoin to make the trail harder to follow. SlowMist founder Cos said anti-money-laundering controls are struggling to keep pace with automated laundering scripts.

Chainflip has been trying to interrupt those flows and said it had rejected at least one deposit, though it refunded the money rather than freezing it. Beyond the two headline cases, PeckShield’s remaining top-10 incidents ranged from $3.15 million to $7.81 million.

The biggest of those smaller cases involved a front-run against the MEV bot yoink, and the funds were returned. Another notable event was the Payment Processor V2 incident tied to the LimitBreak contract, which represented $6.6 million in losses, with $3.4 million returned. During that September 25 white-hat rescue, security researcher Quit moved 23,155 NFTs valued at nearly $6 million out of exposed wallets, although a separate exploit path left 660 WETH unrecovered.

What comes next

Based on the information cited by PeckShield and other security researchers, the main open questions now center on fund recovery and tracing. Bitget has said it will use its protection fund to cover the loss, while the Liquid case already saw a substantial portion of the stolen assets returned.

The confirmed picture for September is that the headline loss figure was driven by two outsized events rather than a broad-based rise across all attacks. Further updates are likely to focus on whether more assets can be recovered, whether laundering routes can be disrupted, and whether the technical claims made around both major incidents hold up under continued scrutiny.

Source: cryptopotato.com