Bitget's $387 Million Bitcoin (BTC) Wallet Breach Anchors 2026's Worst Hack Month
Crypto hack losses hit $766.49 million in September 2026, led by Bitget's $387 million wallet breach. SlowMist traces the compromise to August 31.
AI SummaryAI
- Crypto hack losses reached $766.49 million in September 2026, up 462% from August's $136.3 million.
- Bitget lost about $387 million and Liquid Network about $320 million, roughly 92% of September's total.
- SlowMist traced the earliest malicious activity in the Bitget breach to August 31.
- Liquid Network attackers returned roughly $285 million, including 3,400 BTC.
September Sets a 2026 Loss Record
September closed as the costliest month for crypto security in 2026, with exploited funds reaching $766.49 million, a figure tracked by PeckShield on-chain. The total jumped roughly 462% from August's $136.3 million and passed the previous monthly peak of $646.89 million set in April, when the KelpDAO exploit inflated the damage. Two breaches carried nearly the whole month. Bitget lost about $387 million from its hot wallets, and the Liquid Network, a
Bitcoin (BTC) sidechain, saw roughly $320 million drained, placing the two incidents at about 92% of the monthly total, or $707 million combined. September also set an incident-count record: PeckShield logged 55 major hacks after a then-record 50 in August, while CertiK's dashboard counted 99 security incidents across the month. Thirteen September exploits topped $500,000, but the proceeds concentrated in the largest breaches. The quarter's losses reached $1.2 billion, up 53% from the $819.4 million posted in Q2, with incidents rising 12.8% to 247. The breaches hit custody and bridge infrastructure rather than the Bitcoin (BTC) price mechanism itself.
@PeckShieldAlert · X post
Tracked by PeckShield.
View on X
SlowMist Traces Bitget Breach to August 31
Forensics on the Bitget breach show the compromise began weeks before any funds left. The exchange's official progress report, prepared with blockchain security firm SlowMist and current as of September 29, places the earliest malicious activity on August 31. Attackers exploited a zero-day flaw, a previously unknown bug, in a third-party security product, and investigators recovered a custom-built withdrawal tool from files the intruder had deleted. Stolen private key material then granted access to Bitget's hot wallets, the online storage that holds an exchange's liquid reserves, separate from offline cold storage. SlowMist has not attributed the intrusion to a named group, though Bitget CEO Gracy Chen has previously pointed to suspected North Korean hackers. The theft stands as the largest of 2026, ranking above the Drift Protocol, KelpDAO and LayerZero exploits that led the year's tally before September. The finding matters for every exchange running the same third-party security stack, since the entry point sat outside Bitget's own code.
Liquid Network Funds Flow Back
Not every September loss became permanent. The Liquid Network attackers, who described themselves as white hats, returned about $285 million of the roughly $320 million taken, and the network has since received 3,400
Bitcoin (BTC) back. A $7.81 million maximal extractable value bot front-run also ended with the funds returned, as did part of the damage at Payment Processor V2, which recovered $3.4 million of a $6.6 million loss. Crypto casino Duelbits lost $7 million, and the Nostra oracle exploit cost $3.5 million. An attempt against a Gnosis Safe multisig, the wallet arrangement many DAO treasuries rely on, was pre-empted by a bot named Yoink, and the money came back. After the thefts, funds moved within hours and were mixed over days through DEX swaps, the crypto mixer Tornado Cash and no-KYC venues, with fresh activity converting proceeds into Monero (XMR) and privacy-protected ZCash (ZEC). The remaining 53 incidents cost about $59 million combined, mostly hits of $3 million to $7 million against wallets, bridges and Web3 applications.
A $1.2 Billion Quarter, Net of Returns
Read together, the quarter's losses concentrated in operational compromise rather than contract bugs alone, and Ethereum and BNB Smart Chain absorbed the most attacks across the period. Q3 damage of $1.2 billion ran 53% above Q2's $819.4 million, yet the net figure was lower than the headline: CertiK's dashboard recorded $273.2 million frozen or returned in September, trimming adjusted losses to about $495.3 million. Phishing took more than 11% of Q3 incidents, and attacks kept landing regardless of where the Crypto Fear and Greed Index sat in the cycle. The SlowMist post-mortem frames the remediation: close third-party zero-day exposure, harden key custody and tighten withdrawal controls. With 247 incidents in a single quarter, exchanges and protocols need stricter audits and real-time withdrawal monitoring before the next quarter compounds the damage.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

