‹ BackNewsCrypto Security

Crypto Security

Crypto hack losses topped $766 million in September, the highest monthly total of 2026
Bitget’s $387.5M hack drove Q3 crypto security losses to $1.26 billion, CertiK says
CertiK says Q3 2026 saw 247 security incidents with roughly $1.26 billion in losses
Crypto lost $1.26 billion to hacks in Q3 as bitcoin rose 40% and ETF inflows kept building
Crypto hacks topped $768 million in September, marking the worst month of 2026
Crypto losses topped $768 million in September, with Bitget and Liquid Network accounting for most of the damage
Lazarus Group
2026-09-30 01:10:57

Lazarus and North Korea’s crypto theft network has now been tied to nearly $7.8 billion

The September 2026 Bitget hack has pushed North Korea-linked cyber activity back to the center of the crypto security debate. Bitget first disclosed losses of about $351.6 million, then revised the confirmed amount of transferred assets to $387.5 million. TRM Labs said parts of the laundering trail overlapped with earlier North Korea-linked attacks including Bybit and AFX Bridge, while Elliptic assessed a North Korea connection as “highly likely.” That latest case sits inside a much longer record. Over the past decade, investigators, law enforcement agencies, and security firms have used names such as Lazarus Group, BlueNoroff, APT38, TraderTraitor, Citrine Sleet, Andariel, and Famous Chollima to describe overlapping North Korean cyber units tied to the Reconnaissance General Bureau, or RGB. The naming varies by firm, but the operational pattern is consistent: financial theft, crypto-focused intrusions, malware campaigns, supply-chain compromises, espionage, and covert workforce infiltration. Publicly attributed crypto thefts linked by governments and law enforcement to North Korean actors exceed $3.1 billion based on major named cases alone, including Ronin Bridge, Harmony Horizon Bridge, Atomic Wallet, Stake, DMM Bitcoin, and Bybit. Broader blockchain-tracing estimates are much higher. Chainalysis put the cumulative total at no less than $6.75 billion by the end of 2025, and with the still-unresolved Bitget case added to the picture, the running total cited in the source article approaches $7.8 billion as of September 2026.

800
Lazarus and North Korea’s crypto theft network has now been tied to nearly $7.8 billion
Crypto Securi
2026-09-30 03:00:58

Crypto security’s center of gravity is shifting from code bugs to permissions and trust chains

A TechFlowPost article argues that the biggest security failures in crypto are no longer centered on undiscovered smart contract bugs. Instead, recent losses have clustered around permissions, signing flows, RPC dependencies, supply chains, backend approval systems, and the people trusted to operate them. The piece points to four major incidents — Bybit, Bitget, KelpDAO, and Drift — as evidence that attackers are increasingly bypassing code and going after the trust assumptions wrapped around it. In the article’s framing, the industry has spent years hardening contracts, adding multisigs, separating cold wallets, and expanding audits, yet funds still disappeared because the systems approving transactions were fed false data or because authorized signers were manipulated into approving malicious actions. It also argues that AI is changing the economics of attacks by making social engineering, malware delivery, identity fabrication, and large-scale contract scanning cheaper and easier to automate. The article does not say audits are useless. Its point is narrower: audits cover a shrinking share of the places where money is actually lost. As attack surfaces move outward, the proposed response shifts as well — toward permission governance, infrastructure diversity, runtime controls, continuous monitoring, and insurance structures that price security architecture directly.

130
Crypto security’s center of gravity is shifting from code bugs to permissions and trust chains