Financial losses resulting from cryptocurrency security incidents, exploits, hacks, and scams climbed steeply to reach $1.26 billion during the third quarter of 2026. This dramatic escalation was largely driven by a massive $387.5 million breach that targeted prominent crypto exchange Bitget, underscoring ongoing vulnerabilities within the digital asset ecosystem despite advancements in blockchain security infrastructure and protocols.
According to comprehensive data published by blockchain security and analytics company CertiK, quarterly losses rose by an alarming 53.9% when compared to the second quarter of 2026, during which losses were recorded at $819.4 million. Alongside the surge in stolen capital, the total number of distinct security incidents across the broader crypto landscape also increased by approximately 13%, moving upward from 219 incidents in the previous quarter to 247 incidents in Q3.
The single largest contributor to this quarterly tally was the devastating Bitget hack, which alone accounted for roughly 31% of all losses registered throughout the third quarter. Under CertiK’s strict analytical methodology, this event stands out as the largest recorded security breach of the period. However, the quarter was marred by multiple high-profile exploits that collectively drained hundreds of millions of dollars from various platforms, protocols, and networks.
Ranking second behind the Bitget incident was the Liquid Network exploit that occurred on Sept. 6, which resulted in a staggering $319 million in stolen funds. This was closely followed by a major security failure on Tectonic, which accounted for $120 million in losses, and the Coldcard hardware wallet-related theft, which stripped users and platforms of $112.7 million in July. These major events compounded a troubling quarterly trend that highlighted systemic risks spanning centralized exchanges, decentralized finance protocols, and hardware security devices alike.

The cumulative toll of these events was especially stark during the final month of the quarter. CertiK recorded roughly $769 million in total losses across 99 separate security incidents during September alone. Out of this massive monthly sum, approximately $273 million was ultimately frozen or successfully recovered through rapid collaboration between security researchers, validators, and law enforcement agencies. This intervention brought the adjusted net losses for September down to $495.3 million. Looking closely at the nature of these September breaches, smart contract and protocol exploits accounted for the vast majority of the damage. Across 58 individual exploit incidents, attackers made off with $734 million, representing nearly 96% of the month’s total gross losses.
The defining security event of the quarter—the Bitget exchange breach—unfolded rapidly in late September. Bitget officially detected unauthorized and suspicious transfers originating from a portion of its hot wallets on Sept. 24, prompting the platform to immediately suspend customer withdrawals as an emergency protective measure. In subsequent disclosures, the company revealed that the perpetrators managed to exploit a critical vulnerability embedded within a third-party security product utilized by the platform. By leveraging this external weakness, the attackers were able to successfully obtain sensitive internal administrative credentials and subsequently forge legitimate-looking withdrawal commands to drain the hot wallets.
Subsequent independent technical investigations have shed further light on the origin and timeline of the breach. Prominent blockchain security and anti-money laundering firm SlowMist traced the underlying activity tied to the Bitget hack back to a zero-day exploit that had occurred earlier in the summer, specifically on Aug. 31. This detailed forensic tracking illustrates the sophisticated, premeditated nature of modern crypto attacks, where malicious actors often spend weeks or even months probing infrastructure, securing internal credentials, and mapping out systems before executing massive fund extractions.
As the digital asset industry continues to absorb the staggering financial impact of a $1.26 billion third quarter, stakeholders across the ecosystem face mounting pressure to reevaluate third-party vendor risk, hot wallet architectural safety, and real-time monitoring systems. With quarterly security metrics deteriorating significantly compared to the spring months, the imperative for robust, proactive security measures and cross-industry intelligence sharing remains higher than ever for centralized exchanges and decentralized protocols alike.