Crypto security losses hit about $730 million in September as exchange backends and core infrastructure drew attacks

Crypto security losses hit about $730 million in September as exchange backends and core infrastructure drew attacks

N
News Editor
2026-10-08 07:13:05
A monthly security report cited by Foresight said the crypto sector lost about $730 million to security incidents in September 2026, making it the worst month of the year so far by reported outflows. Two cases dominated the total: a backend manipulation attack tied to Bitget hot-wallet infrastructure caused about $387.5 million in losses, while a validator software flaw on Liquid Network accounted for about $319 million. Together, they made up more than 95% of the month’s losses. The report said the headline number reflects incident reports and fund outflows rather than final unrecoverable losses. In the Liquid Network case, the attacker later returned roughly 85% of the stolen funds, or about $272 million, leaving about $47 million still outstanding. Beyond those two major incidents, the report listed attacks involving governance proposal manipulation, oracle price distortion, hot-wallet key exposure, bridge drainage, phishing, address poisoning and meme-coin rug pulls. The main shift identified in September was the move away from direct smart-contract exploitation toward exchange backends, validator software, bridge systems and other infrastructure layers. The report also included suggestions for users, projects and the broader industry, ranging from avoiding unofficial links and unlimited approvals to tightening governance thresholds, reviewing backend authorization systems and monitoring third-party security supply-chain risks.

A September 2026 security report cited by Foresight put total crypto losses from security incidents at about $730 million for the month, with exchange backend systems and lower-layer infrastructure emerging as the main targets.

Crypto security losses hit about $730 million in September as exchange backends and core infrastructure drew attacks 2

The report, compiled from data gathered by several blockchain security monitoring platforms, said a backend manipulation attack involving Bitget hot-wallet infrastructure caused about $387.5 million in losses, while a validator software exploit on Liquid Network led to roughly $319 million in losses. Those two incidents alone accounted for more than 95% of the monthly total, making September the worst month of 2026 so far by reported losses.

The report added an important caveat: the $730 million figure refers to incident reports and fund outflows, not necessarily final net losses. In the Liquid Network case, about 85% of the stolen funds, or roughly $272 million, had already been returned. About $47 million remained outstanding at the time of the report.

It also described a broader change in attack patterns. September saw backend manipulation, validator software flaws, governance proposal abuse, oracle price manipulation, cross-chain bridge drainage and DEX liquidity-pool attacks all appear in the same month. In the report’s reading, attackers are moving away from the smart-contract layer and toward infrastructure.

Six major hacking incidents

Bitget hot-wallet backend manipulation attack

The Bitget incident took place on Sept. 25 and caused losses of about $387.5 million. According to the report, the attacker exploited a zero-day flaw in a third-party security product to obtain high-privilege internal credentials, then forged withdrawal instructions and bypassed risk-control checks. Funds were moved out of Bitget hot-wallet and warm-wallet infrastructure across Ethereum, XRP, BSC, Arbitrum and Avalanche.

Bitget said private keys were not compromised, cold wallets were unaffected and user balances were not impacted. The exchange said losses would be covered by a user protection fund worth more than $464 million. It also said the affected systems had been isolated, internal credentials had been reset and multiple security firms were assisting with the investigation and on-chain tracing.

Crypto security losses hit about $730 million in September as exchange backends and core infrastructure drew attacks 3

Liquid Network validator software exploit

The Liquid Network attack happened on Sept. 6 and resulted in losses of about $319 million. The attacker exploited a range-proof cache collision bug in Elements, the validator software used by Liquid Network, and minted about 4,000 L-BTC without real asset backing. Those tokens were then redeemed for real bitcoin through SideSwap’s peg-out mechanism.

The report said an attacker identifying as a white hat later negotiated with Blockstream through on-chain messages and returned about 3,400 BTC after the flaw was fixed. That represented around 85% of the stolen funds. About 598.5 BTC, valued in the report at roughly $47 million, had not been returned.

Neutron governance proposal manipulation

On Sept. 22, Neutron suffered a governance attack that led to about $4.4 million in losses. The attacker spent only about 20,199 USDC to buy roughly 31.6 million NTRN, then staked the tokens about 12 minutes before voting ended. A malicious governance proposal passed with about 82% support.

After the vote, the attacker gained admin control over 11 contracts and migrated them to malicious code, eventually stealing about $4.4 million in assets. Cosmos Hub validators later coordinated a network halt of around 25 hours and moved about 1.23 million ATOM from addresses linked to the attacker as part of asset recovery efforts.

Duelbits hot-wallet private key exposure

Duelbits, a crypto gambling platform, was attacked on Sept. 24 in what the report described as a likely private-key leak rather than a smart-contract exploit. Losses were put at about $7 million. The attacker gained direct control of the hot wallet and transferred about 836 ETH, 1.62 million USDT, 97,000 USDC, 31,500 DAI, 12.4 billion SHIB and 8.1 BTC to a new address, then swapped most of the funds into ETH and consolidated them into one address.

Crypto security losses hit about $730 million in September as exchange backends and core infrastructure drew attacks 4

A Duelbits co-founder confirmed losses of about $7 million and said user funds were safe. The platform would remain offline until the investigation ends and the hot wallet is replenished.

Nostra oracle price manipulation

Nostra was hit on Sept. 17 in an oracle manipulation attack that caused about $3.5 million in losses. The attacker created a fake liquidity pool and paired it with wash trading, pushing the quoted price of the NSTR token from about $0.006 to about $49.5, nearly an 8,000x increase.

Because Nostra’s lending protocol relied on a third-party price source that read the manipulated pool, the attacker used the inflated NSTR as collateral and borrowed about $3.5 million worth of ETH, STRK, USDC, USDT, WBTC and DAI from the Starknet money market. The report said about $1.92 million of the stolen assets, including 234.57 ETH and 1.3 million DAI, was later bridged to Ethereum. Nostra suspended lending, withdrawals and liquidations after the incident.

Payy Network bridge exploit

Payy Network’s Ethereum bridge was attacked at 4:21 UTC on Sept. 24, causing about $1.83 million in losses. The attacker drained the bridge’s full balance, about $1.8 million in USDC, then used the privacy protocol Railgun to obscure the funding trail and swapped the USDC into ETH.

The report described Payy Network as a rollup project that provides on-chain payroll and treasury services. The team said the lost funds were non-custodial assets deposited by users, but it had not disclosed the exact cause of the vulnerability. Operations were suspended after the attack.

Crypto security losses hit about $730 million in September as exchange backends and core infrastructure drew attacks 5

Rug pulls and phishing scams

The report also listed several rug-pull and phishing cases recorded during the month.

  • On Sept. 16, a victim using an Ethereum address beginning with 0xe268 lost $565,768 in sUSDat after signing a phishing signature.
  • On Sept. 25, a user on Ethereum lost $67,572 in USDT in an address-poisoning attack. The report listed the intended address as 0xca16b299700674dda6941baa1bdeeff6d90fd94b and the poisoned address as 0xca166632d25ea74baa93a5303aa73f61e80fd94b.
  • On Sept. 26, a user on XRP Ledger signed a phishing transaction and lost $37,927 worth of XRP. The victim address was rGtghKcmYY8gdUQwQerY5Ruww2LvdbgWVh.

DYORSWAP fake-mainnet phishing case

On Sept. 27, scammers set up a fake GIWA mainnet and integrated a fake cross-chain RPC into DYORSWAP, luring users into sending ETH to a fake bridge contract. The report said roughly $2 million was stolen. GIWA later said its mainnet had not launched, and the DEX project started compensation for affected funds.

Trezor email vendor breach

In September, Brevo, the email service provider used by Trezor, was breached. The attacker obtained parts of customer contact data and sent phishing emails disguised as official security alerts to about 347,000 Trezor users, prompting them to download malicious software and enter wallet backup passwords.

The report said the notable feature of this case was that the attacker did not target the wallet directly. Instead, the compromise began with an upstream service provider, then used exposed user data for highly targeted phishing.

Robinhood Chain meme-coin rug-pull series

This set of incidents ran from July 10 to Sept. 21 and was disclosed on Sept. 27. The report said losses reached at least $18.43 million. On-chain analysis pointed to at least 53 meme-coin issuance projects on one chain that may have been linked to the same operating group.

Crypto security losses hit about $730 million in September as exchange backends and core infrastructure drew attacks 6

According to the report, the team used a large number of connected wallets to acquire more than 70% of token supply shortly after launch, drew in retail buyers through project momentum, then sold into the market. In some projects, internal wallets controlled 82% to 86% of supply. The proceeds from one project were then used to launch the next, creating a repeated cycle of issuance, concentrated control, buyer attraction, dumping and relaunch.

Report conclusions and recommendations

The report said the shift from smart-contract exploits to lower-layer infrastructure became clearer in September 2026. Beyond the two largest cases involving Bitget and Liquid Network, it also pointed to a FastSwap liquidity-pool flash attack, the manipulated Nostra oracle, the drained Payy Network bridge and the Duelbits hot-wallet key leak as signs of the same pattern: attackers are systematically looking for weaknesses in infrastructure rather than attacking contract code head-on.

It also argued that trusted systems have themselves become an attack surface. In the Bitget case, the attacker obtained internal credentials through a zero-day in a third-party security product, forged withdrawal instructions and bypassed risk controls without touching private keys. In the Liquid Network case, a flaw in validator software was enough to move assets worth hundreds of millions of dollars.

The security team at Zero Hour Technology recommended that individuals avoid crypto links suggested by AI tools and use official channels instead, avoid signing unlimited approvals and clear existing approvals regularly. For projects, it suggested higher thresholds and delayed execution for governance proposals, dedicated audits for validator software and cache mechanisms, deeper checks on data integrity in exchange backend authorization systems and tighter monitoring of abnormal trading in DEX liquidity pools. At the industry level, it called for exchange backend security standards, stronger monitoring of third-party security supply-chain risk and continued attention to evolving tactics used by state-level APT groups such as North Korea’s Lazarus Group.

The original article also included a disclaimer stating that markets carry risk and the article does not constitute investment advice.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.