Exploits Account for 95% of September's $766.4 Million in Web3 Losses as Quarterly Theft Rises 54%
Key Takeaways
- •September 2026 cryptocurrency losses totaled approximately $766.4 million, the highest monthly figure of the year, coinciding with the largest number of confirmed incidents in any single month of 2026.
- •The Bitget exchange breach at $387.5 million and the Liquid Network incident at roughly $318.6 million together represented more than 90% of September's losses, dwarfing the third-largest incident at $7.8 million.
- •Approximately $270.6 million, about 35% of the month's gross losses, has since been recovered or frozen, leaving roughly $495.8 million unresolved.
- •Exploits were responsible for roughly 95.5% of September's losses despite accounting for 58 of approximately 99 confirmed incidents, highlighting a wide gap between attack frequency and severity.
- •Third-quarter 2026 losses climbed 53.9% quarter-over-quarter to $1.26 billion, while adjusted losses excluding recovered funds rose 10% to $869.6 million, indicating a broader decline in security conditions.

Approximately $766.4 million was lost to cryptocurrency security incidents in September 2026, according to a report published by blockchain security firm CertiK. The total sets a new record for the highest monthly losses this year and coincides with the largest number of confirmed incidents recorded in any single month of 2026.
The month's losses were heavily concentrated. Cryptocurrency exchange Bitget accounted for the largest single event at $387.5 million, followed by the Liquid Network, a federated Bitcoin sidechain, at approximately $318.6 million. Together, the two events represent more than 90% of all September losses, dwarfing the third-largest incident, which came in at $7.8 million. Roughly $270.6 million of the month's total — about 35% of the gross figure — has since been recovered or frozen, softening — but far from eliminating — the net impact on the industry.
The concentration of losses reflects a familiar dynamic in Web3 security: while incident counts are distributed widely across protocols and chains, a small number of large-scale breaches against centralized targets continue to account for the bulk of stolen funds.
Exploits Dominate as Quarterly Losses Climb 54%
CertiK's breakdown of attack vectors shows a striking asymmetry. Exploits — attacks that abuse vulnerabilities in code, infrastructure, or operational processes — were responsible for $33.8 million, or roughly 95.5% of September's losses. Private key compromises accounted for $14.2 million, wallet compromises for $11.9 million, and phishing for just $6.2 million.
The incident count tells a different story. Of the month's approximately 99 confirmed incidents, 58 were categorized as exploits, while 13 were phishing attacks and 11 involved private key compromises — meaning the most frequent attack types were far from the most damaging.
By category, losses were highest across multiple chains, while Ethereum recorded the most individual incidents, underscoring that the largest exposures now span cross-chain infrastructure rather than any single network. Consistent with the monthly figures, centralized exchanges suffered the largest share of losses, followed by mainnet-related incidents — a distribution in line with the dominance of the month's two largest events.
The September surge also shaped a bleak quarterly picture. Total losses in Q3 2026 reached $1.26 billion, up 53.9% from $819.4 million in Q2, while the number of incidents rose 12.8% to 247. Adjusted losses — which exclude recovered or frozen funds — climbed 10% quarter-over-quarter to $869.6 million, indicating that the increase is not merely the result of a few outsized events but part of a broader deterioration in the security environment. Those figures now set the benchmark for the final stretch of 2026, and the eventual disposition of the roughly $495.8 million in September losses not recovered or frozen will determine how the month's net toll is ultimately recorded.
Taken together, the data points to a widening gap between incident frequency and incident severity. For developers and security teams, the implication is that hardening application-layer code remains necessary but insufficient: as September demonstrated, a single vulnerability in an exchange backend or cross-chain infrastructure can expose more value in one event than hundreds of smaller exploits combined.