Bitget’s $387.5M hack drove Q3 crypto security losses to $1.26 billion, CertiK says

Bitget’s $387.5M hack drove Q3 crypto security losses to $1.26 billion, CertiK says

N
News Editor
2026-10-01 13:35:47
Crypto security losses hit $1.26 billion in the third quarter of 2026 across 247 incidents, according to blockchain security firm CertiK, with September alone contributing about $769 million. The sharp rise was largely tied to Bitget’s $387.5 million hack, which represented roughly 31% of all losses recorded during the quarter and ranked as the largest incident in CertiK’s Q3 dataset. Q3 losses were up 53.9% from $819.4 million in Q2, while the number of incidents rose about 13%, from 219 to 247. CertiK also said around $273 million from September incidents was frozen or returned, bringing adjusted losses for the month to $495.3 million. During September, exploits accounted for $734 million in losses across 58 cases, or nearly 96% of the monthly total. Bitget said it detected unauthorized transfers from some hot wallets on Sept. 24 and suspended withdrawals. The exchange said attackers exploited a vulnerability in a third-party security product, obtained internal credentials and forged withdrawal commands.

Crypto security losses reached $1.26 billion in the third quarter of 2026 across 247 incidents, according to blockchain security company CertiK. September alone accounted for roughly $769 million of that total.

The jump was driven in large part by the $387.5 million hack of crypto exchange Bitget. Q3 losses rose 53.9% from $819.4 million in the second quarter, while the number of incidents increased about 13%, from 219 to 247.

Bitget was the largest incident in CertiK’s Q3 data

CertiK said the Bitget hack made up about 31% of all losses recorded in the quarter, making it the largest incident tracked under the firm’s methodology for Q3 2026.

The second-largest event was Liquid Network’s $319 million exploit on Sept. 6. Tectonic followed with $120 million in losses, and the Coldcard theft ranked next at $112.7 million.

September recorded 99 incidents

CertiK recorded about $769 million in losses across 99 security incidents in September. Of that amount, around $273 million was frozen or returned, leaving adjusted losses of $495.3 million.

Across 58 incidents, exploits accounted for $734 million, or nearly 96% of the month’s losses.

Bitget said attackers used a third-party security flaw

Bitget said it detected unauthorized transfers from some of its hot wallets on Sept. 24 and suspended withdrawals. The company said attackers exploited a vulnerability in a third-party security product to obtain internal credentials and forge withdrawal commands.

A related item linked in the source said SlowMist traced Bitget hack activity to an Aug. 31 zero-day exploit.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.