Crypto security losses reached $1.26 billion in the third quarter of 2026 across 247 incidents, according to blockchain security company CertiK. September alone accounted for roughly $769 million of that total.
The jump was driven in large part by the $387.5 million hack of crypto exchange Bitget. Q3 losses rose 53.9% from $819.4 million in the second quarter, while the number of incidents increased about 13%, from 219 to 247.
Bitget was the largest incident in CertiK’s Q3 data
CertiK said the Bitget hack made up about 31% of all losses recorded in the quarter, making it the largest incident tracked under the firm’s methodology for Q3 2026.
The second-largest event was Liquid Network’s $319 million exploit on Sept. 6. Tectonic followed with $120 million in losses, and the Coldcard theft ranked next at $112.7 million.
September recorded 99 incidents
CertiK recorded about $769 million in losses across 99 security incidents in September. Of that amount, around $273 million was frozen or returned, leaving adjusted losses of $495.3 million.
Across 58 incidents, exploits accounted for $734 million, or nearly 96% of the month’s losses.
Bitget said attackers used a third-party security flaw
Bitget said it detected unauthorized transfers from some of its hot wallets on Sept. 24 and suspended withdrawals. The company said attackers exploited a vulnerability in a third-party security product to obtain internal credentials and forge withdrawal commands.
A related item linked in the source said SlowMist traced Bitget hack activity to an Aug. 31 zero-day exploit.

