Crypto Security Losses Hit $1.26 Billion in Q3, Led by Bitget Hack: CertiK
Key Takeaways
- •Quarterly crypto security losses rose 53.9% to $1.26 billion in Q3 2026, while the number of incidents grew only about 13% to 247, pushing the average loss per incident to roughly $5.1 million from $3.7 million in Q2.
- •The $387.5 million Bitget hack, the quarter's largest incident at about 31% of total losses, was traced by SlowMist to a zero-day exploit staged 24 days before its Sept. 24 detection, with attackers leveraging a third-party security product to forge withdrawal commands.
- •Four attacks — Bitget, Liquid Network's $319 million exploit, Tectonic's $120 million loss, and the $112.7 million Coldcard theft — together accounted for roughly $939 million, or nearly three-quarters of Q3's losses.
- •Exploits were the dominant loss category in September, causing $734 million across 58 incidents, or nearly 96% of the month's losses.
- •About $273 million was frozen or returned in September, more than a third of the month's gross figure, leaving adjusted losses of $495.3 million.

Crypto security losses climbed to $1.26 billion in the third quarter of 2026, with the $387.5 million hack of crypto exchange Bitget driving much of the increase, according to data from blockchain security firm CertiK.
The quarterly total spanned 247 security incidents, an increase of roughly 13% from the 219 recorded in Q2. Dollar losses rose 53.9% from $819.4 million in the second quarter, and September alone accounted for approximately $769 million of the quarterly figure — about 61% of the total. The sharper rise in dollar losses than in incident counts also implies an average loss per incident of roughly $5.1 million in Q3, up from about $3.7 million in Q2.
The Bitget hack represented about 31% of Q3 losses, making it the largest incident recorded during the quarter under CertiK's methodology. Liquid Network's $319 million exploit on Sept. 6 ranked second, followed by Tectonic at $120 million and the $112.7 million Coldcard theft. Together, those four incidents account for roughly $939 million, or nearly three-quarters of the quarter's losses, underlining how concentrated Q3's damage was in a small number of large-scale attacks.
Within September, CertiK recorded roughly $769 million in losses across 99 security incidents. About $273 million of that amount was frozen or returned — more than a third of the month's gross figure — leaving adjusted losses of $495.3 million for the month. The gap between the gross and adjusted totals shows how much freeze and recovery outcomes shape the final accounting of a period's losses. Exploits were the dominant loss category, accounting for $734 million across 58 incidents, or nearly 96% of September's total losses.
The Bitget incident came to light on Sept. 24, when the exchange detected unauthorized transfers from some of its hot wallets and suspended withdrawals. According to the company, attackers exploited a vulnerability in a third-party security product to obtain internal credentials and forge withdrawal commands, an attack path that ran through an external dependency in the exchange's security stack. The detection date also marks only part of the timeline: related coverage indicates SlowMist traced the hack's activity to an Aug. 31 zero-day exploit, 24 days before the unauthorized transfers were detected.
Related: SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit