Crypto security losses surge to $1.26B in Q3, CertiK says; Bitget hack is 31% of total

security⚖️ NeutralSignal 76

⏱ 2 min read

September contributed about $769 million, while two incidents — Bitget and Liquid Network — made up roughly 56% of the quarter’s losses.


Crypto security losses climbed to $1.26 billion in the third quarter of 2026 across 247 incidents, according to blockchain security firm CertiK. That is a 53.9% increase from $819.4 million in Q2, with the incident count rising about 13% from 219 to 247.

Losses were heavily concentrated in a few large breaches. CertiK said the $387.5 million hack of crypto exchange Bitget accounted for about 31% of Q3 losses, the largest incident under its methodology. The Liquid Network exploit on Sept. 6 ranked second at $319 million. Tectonic followed at $120 million, and CertiK recorded a $112.7 million Coldcard theft. By our calculation, the top two incidents alone represented roughly $706.5 million — about 56% of the quarter’s total.

The month of September was the high-water mark. CertiK recorded roughly $769 million in losses across 99 incidents. About $273 million was frozen or returned, leaving adjusted September losses of $495.3 million. That implies roughly 35.5% of September’s gross losses were mitigated through freezes or recoveries. Exploits did most of the damage: across 58 exploit incidents, losses totaled about $734 million, nearly 96% of September’s figure.

The jump in value lost outpaced the rise in incident count, indicating higher severity. Using CertiK’s totals, the average loss per incident increased to about $5.1 million in Q3 (calculated from $1.26 billion over 247 incidents) from roughly $3.7 million in Q2 (from $819.4 million over 219 incidents), an increase of about 36%.

Bitget said it detected unauthorized transfers from some of its hot wallets on Sept. 24 and suspended withdrawals. According to the company, attackers exploited a vulnerability in a third-party security product to obtain internal credentials and forge withdrawal commands. That description underscores two known pressure points in crypto security: exposure from vendor dependencies and the inherent risk of hot-wallet infrastructure.

The tally presents a blunt picture but lacks granularity beyond named cases. CertiK’s aggregate figures do not provide a sector breakdown for the quarter, and classifications and adjustments (such as recoveries) follow its own methodology. Additional disclosures or recoveries could change net loss figures, particularly for September.

For risk monitoring, two variables will matter in the coming prints: how much of reported monthly losses are ultimately frozen or returned, and whether the share of losses attributed to exploits eases from September’s near-96% level. A sustained pace near September’s totals — or another outsized breach — would keep quarterly figures elevated.


This content is for informational purposes only and does not constitute financial advice.

🧠 HafidWatch Take

The sharp increase in average loss per incident—rising by about 36% from Q2 to Q3—suggests that the growing financial impact of each breach may pose a greater systemic risk than the number of incidents alone. This concentration of losses in a few major exploits underscores how vulnerability in critical infrastructure or third-party components can disproportionately destabilize the broader crypto ecosystem. Monitoring not just how often breaches occur but how severe they are will be crucial for assessing ongoing crypto security risks.

Daily crypto intelligence. Before the market opens.

Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.

✓ Free forever  ·  ✓ No spam  ·  ✓ 50+ sources monitored

Want it faster? Join the community:

Type above and press Enter to search. Press Esc to cancel.