Crypto Security Losses Reach $1.26 Billion in Q3 2026 as Bitget Hack Accounts for $387.5 Million
Key Takeaways
- •Q3 2026 crypto security losses totaled $1.26 billion across 247 reported incidents, averaging roughly $5.1 million per incident, per a CertiK snapshot.
- •The Bitget exchange hack, at $387.5 million, accounted for approximately 31% of the quarter's total losses and was the largest single event.
- •CertiK's dashboard revised the quarterly total upward to $1.27 billion across 249 incidents on October 2, 2026, a 54.4% increase over Q2's $819.4 million.
- •Earlier 2026 CertiK data showed five incidents comprising nearly 59% of the year's total losses, indicating aggregate figures are repeatedly driven by outlier events.
- •Threats are diversifying beyond exchange breaches, with TRM Labs reporting that deepfake scam losses in 2026 are already 263% above 2025 levels.

Crypto security losses totaled $1.26 billion in the third quarter of 2026, and a single breach — the hack of exchange Bitget — accounted for $387.5 million of that total. The figures, drawn from a CertiK data snapshot reported by Cointelegraph, underline how one major incident can define an entire quarter's loss picture for the industry.
The Quarter's Key Figures
According to the CertiK snapshot, total crypto security losses in Q3 2026 reached $1.26 billion across 247 reported incidents. Spread across that count, the total works out to an average of roughly $5.1 million per reported incident — a baseline that helps frame just how far above the norm the quarter's largest events landed. The Bitget hack was the largest single event, at $387.5 million, making it the dominant loss event of the quarter.
A subsequent update to CertiK's live dashboard, published October 2, 2026, revised the quarterly total upward to $1.27 billion across 249 incidents. The Bitget figure remained unchanged at $387.5 million. The headline numbers in this article are based on the earlier $1.26 billion figure from the Cointelegraph snapshot, which is the basis for the reported totals. Because the dashboard functions as a rolling tracker, the quarter's totals may continue to be revised as further updates are published, a dynamic worth watching as the quarter's final loss picture settles.
How One Hack Dominated the Quarter
Set against the $1.26 billion quarterly total, the Bitget incident represented approximately 31% of all Q3 crypto security losses. That degree of concentration matters: when a single exchange absorbs nearly a third of a quarter's losses, it signals that platform-level security remains the single biggest vulnerability in crypto.
Other named Q3 incidents included Liquid Network at $319 million, Tectonic at $120 million, and Coldcard at $112.7 million, according to the Cointelegraph report.
The pattern of a small number of large incidents dominating aggregate losses is not new. Earlier CertiK data covering 2026 showed five incidents making up nearly 59% of total losses for the year, suggesting the industry's overall loss figures are repeatedly shaped by outlier events rather than a broad, even distribution of smaller breaches.
Losses Accelerate Quarter-on-Quarter
The scale of losses is growing between quarters. CertiK's dashboard shows Q3's revised $1.27 billion total against $819.4 million in Q2, an increase of 54.4%.
The Bitget Token (BGB) was trading at $1.99 at the time of writing, up roughly 4.2% over the prior 24 hours. The broader crypto market sentiment index sat at 67 out of 100, a reading classified as "Greed," suggesting the market has not broadly repriced risk following the quarter's losses.
A Rising Regulatory Bar for Disclosure
The Q3 figures arrive in a regulatory environment where disclosure expectations are rising. The U.S. Securities and Exchange Commission's 2023 cybersecurity rules require registered public companies to disclose material cyber incidents, generally within four business days of determining that an incident is material. Those rules apply to SEC registrants; no evidence in the available sources establishes that Bitget holds that status. For firms outside that registrant perimeter, the SEC's four-business-day clock does not apply, leaving the timing of public disclosure to each company's own announcements.
What the Figures Mean for Holders
For regular crypto holders, the practical takeaway from these numbers concerns where assets are held. Funds kept on a centralized exchange are exposed to that platform's security. Hardware wallets and self-custody remove that specific risk, though they introduce their own.
The threat landscape is also diversifying beyond exchange breaches. Immunefi's July data showed $110 million in hacks for the month, while TRM Labs found that deepfake scam losses in 2026 are already 263% above 2025 levels. Taken together with the Q3 concentration figures, the data indicate that threats are diversifying rather than concentrating solely on exchanges. Understanding where assets sit, and what protections are in place, remains the most concrete step any holder can take.
Source: CoinLineup
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.