Skip to content
CRYPTO & DECENTRALIZED TECH

Crypto Security Incidents Surge to $1.26 Billion in Q3 2026, Led by Massive Bitget Breach

Financial losses resulting from cryptocurrency security incidents climbed dramatically to reach $1.26 billion in the third quarter of 2026, a massive upward trajectory largely driven by a single devastating breach involving major crypto exchange Bitget, which suffered a staggering $387.5 million hack.

According to comprehensive data published by blockchain security firm CertiK, the overall losses surged by 53.9% compared to the previous quarter, when industry-wide damages sat at $819.4 million. Alongside the spike in stolen capital, the total number of recorded security incidents also saw an upward trend, rising approximately 13% from 219 incidents in the second quarter to 247 incidents in the third.

The single largest contributing event of the period was the Bitget exploit, which alone accounted for roughly 31% of the total losses recorded throughout the entire third quarter, making it the most significant security breach tracked under CertiK’s analytical methodology. Following closely behind the Bitget incident was the Liquid Network exploit, which occurred on Sept. 6 and resulted in a massive $319 million loss before white-hat intervention efforts eventually clawed back substantial funds. Rounding out the top catastrophic events of the quarter were the Tectonic protocol incident, which accounted for $120 million in losses, and the Coldcard hardware security-related theft, which drained $112.7 million from victims.

Bitget’s $388M hack pushes Q3 crypto security losses past $1B

The severity of the third quarter was further underscored by a deeply damaging month of September, during which CertiK recorded roughly $769 million in gross losses spread across 99 separate security incidents. Out of that immense monthly total, collaborative recovery and freezing efforts successfully intercepted about $273 million, allowing platforms and security teams to return or secure those assets before they could be fully laundered. This intervention brought the adjusted net losses for September down to $495.3 million. Protocol exploits proved to be the overwhelmingly dominant vector of attack during the month, accounting for $734 million—or nearly 96%—of the total monthly losses across 58 distinct exploitation events.

The defining event of the quarter for institutional trading platforms occurred on Sept. 24, when cryptocurrency exchange Bitget detected a series of unauthorized and suspicious transfers originating from a selection of its hot wallets. In response to the breach, the company moved swiftly to suspend all customer withdrawals in an effort to contain the bleeding and assess the scope of the compromise. Initial disclosures from the exchange revealed that the malicious actors managed to exploit a critical vulnerability embedded within a third-party security product utilized by the platform. This external vulnerability allowed the attackers to successfully compromise internal system credentials, which they subsequently used to forge fraudulent withdrawal commands, bypassing standard internal safety checks.

Subsequent forensic investigations by independent blockchain security firms, including an extensive analysis by SlowMist, traced the underlying roots of the Bitget breach activity further back, pointing toward a zero-day exploit that had been active since late August. These findings highlighted the compounding risks that centralized cryptocurrency exchanges face when integrating third-party software and security infrastructure into their core operational architecture, as a single weak point in an auxiliary service can cascade into hundreds of millions of dollars in losses.

As the digital asset industry continues to grapple with sophisticated threat actors, advanced exploit techniques, and the persistent threat of zero-day vulnerabilities, the record-breaking figures of the third quarter underscore the mounting urgency for improved code auditing, more resilient hot wallet management, and stricter third-party vendor risk assessments across the entire Web3 ecosystem.

Leave a Reply

Your email address will not be published. Required fields are marked *