Crypto Lost $768 Million In September, And Two Hacks Did 92 Percent Of It
September's $768 million in hack losses came almost entirely from a $388 million Bitget breach and a $320 million Liquid Network exploit. The interesting part isn't the total. It's that $270 million came back, and what that says about attacker economics going forward.
I keep a spreadsheet of hack losses. Yeah, it's a weird hobby, but somebody has to do it, and after you stare at the same columns for three years you start noticing things the headlines miss. September's number came in at $768 million. That's the worst month of 2026, and it isn't particularly close.
Two events did almost all of the damage. A $388 million breach at Bitget, and a $320 million exploit on Liquid Network. More than $270 million of that Liquid money got returned, which is genuinely unusual and worth its own paragraph later. But before we get to that, let's sit with the raw figure for a second.
Because $768 million isn't just a bad month. It's a reminder about where the actual risk sits in this industry.
The Numbers Underneath The Numbers
Start with the math, since the math is where the story actually lives. Bitget plus Liquid is $708 million of the $768 million total. That's 92 percent of September's losses coming from two incidents. Everything else that happened that month, and plenty did happen, adds up to roughly $60 million.
That distribution matters more than the headline. It tells you losses don't spread evenly across some broad attack surface. They cluster. One or two events per month account for nearly everything, and the rest is noise. So if you're trying to model your own risk, you aren't modeling a hundred small probabilities. You're modeling a handful of catastrophic ones.
Now the Liquid piece. $320 million taken, more than $270 million returned. That's a recovery rate north of 84 percent, and honestly, it's the most interesting data point in the whole month. Exploits usually end with funds tumbling through mixers and everyone writing the money off. Getting most of it back suggests the attacker got pressured, or the funds never fully left a controlled environment, or there's coordination happening that normally doesn't happen.
We don't have a full post-mortem on either incident yet, and I'd rather not pretend otherwise. What I can tell you is that an 84 percent recovery changes the economics of attacking a chain. If you can only count on keeping a sixth of what you steal, the expected value of the whole operation falls apart. That's a deterrent, and it's a stronger deterrent than any audit report.
Which brings me to something I've been saying for a while. The real bottleneck in crypto security was never the cryptography.
Where The Risk Actually Lives
Think about what a $388 million exchange breach means mechanically. It doesn't mean someone broke elliptic curve signatures. It means keys, or access, or an internal process failed somewhere. Custody is the soft layer. Always has been. You can have the most mathematically sound execution environment on earth and still lose nine figures because a credential leaked.
And that gets worse as the stack gets more modular. Every bridge, every sequencer, every relayer is another place where trust has to be placed somewhere, and trust placed somewhere is trust that can be revoked by the wrong person. Data availability layers, shared sequencers, intent-based routing, they all make the system faster and cheaper. They also multiply the number of components that each need to be individually correct.
That's the tradeoff nobody puts in the pitch deck. Throughput is table stakes now. Everyone's got cheap blocks. The differentiator is whether your cheap blocks hold up when someone with real money comes looking for the seam.
Here's the thing about September specifically. The two big events hit very different parts of the industry. An exchange is a centralized custody problem. Liquid is a Bitcoin sidechain with a federated model, which is a very different set of trust assumptions. So you can't write this off as centralized exchanges bad, decentralized everything good. Both models got punched in the same month, and the total topped anything we've seen in 2026.
Who loses from that? Retail, mostly, at least short term. Confidence takes a hit, withdrawal queues spike, and the people with the least ability to absorb a loss end up holding the bag. Who wins? Compliance vendors, insurance desks, and honestly, the chains with boring, conservative, heavily tested designs. Boring is a feature. Nobody cares about infrastructure until it breaks, and September broke twice.
What I'd Actually Do With This
My honest read is that the $768 million number is going to get cited for the next year as proof that crypto is unsafe, and that's the wrong takeaway.
First, because $768 million is a small percentage of the total value secured onchain at this point. The industry is much bigger than it was in 2022, and a month like this, while ugly, doesn't threaten the rails. Second, because the recovery rate on Liquid suggests something is actually improving. Enforcement, tracking, and pressure on attackers are all getting better. That's progress you can measure instead of just hope for.
What I'd watch instead of the headline number is the composition. If next month's losses come mostly from key management and custody again, that's a solvable problem with better engineering and stricter operational discipline. If they start coming from sequencer-level or data availability attacks, that's a much harder problem, because those are architectural. You can't patch your way out of a design decision.
So here's my blunt advice. Stop evaluating a chain by its TPS chart. Start asking who holds the keys, how many independent parties have to collude to drain it, and what the recovery path looks like when something goes wrong. Those three questions will tell you more about your actual risk than any dashboard.
And if you're running infrastructure, assume this month happens to you. Not might. Will. The teams that come out of September intact are the ones who already assumed the worst and built for it, and they're not the ones posting about their uptime metrics either.
Recovery matters more than prevention at this point, because prevention has a ceiling and an attacker only needs to be right once. Getting 84 percent of the money back is a better story than losing nothing at all, and that's a strange sentence to write. But here we're, and the scaling roadmap just got a lot more interesting.
Explore More
Key Terms Explained
An approval term meaning authentic, bold, or worthy of respect.
The first cryptocurrency, created in 2009 by the pseudonymous Satoshi Nakamoto.
A protocol that lets you move tokens between different blockchains.
Following the laws and regulations that apply to financial activities, including crypto.