Invest1 publisher2 min readPublished
Bitget's wallet breach accounts for about four-fifths of September's crypto theft after returns
Bitget lost about $387.5 million to forged withdrawals from its wallet system, more than half of September's $742 million in crypto thefts. Most of Liquid Network's loss was handed back, so what stayed stolen sits mainly with one exchange's withdrawal infrastructure.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Liquid Network lost about $319 million to $320 million on September 6 when a flaw in how it verified its bitcoin peg let unbacked L-BTC be minted.
- PeckShield counted $766.5 million stolen in 55 major incidents, about 462% more than August's $136.3 million.
- September alone holds roughly a third of the money stolen in crypto hacks so far in 2026.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Exchange account holders were the most exposed group in September, since the biggest single loss ran through infrastructure tied to a platform's own wallet system.
- contradiction Trackers' return figures run from about $270 million to $285 million, and on the highest of them Bitget's share of what stayed stolen rises to about 85%.
- constraint Coldcard owners cannot fix the flaw with a firmware update, because a seed created on vulnerable code stays weak; the only remedy is moving funds to a freshly generated seed.
Only one of the two big failures was platform infrastructure. Bitget's loss, the largest single theft of 2026 [9], came through infrastructure tied to the exchange's own wallet system [8]. Liquid Network's was a bug in protocol code [10]. On gross figures they take roughly 52% and 43% of Immunefi's $742 million [1][2].
Returns change the split. Parties claiming to be white hats handed back about $285 million of Liquid's loss [11], leaving roughly $35 million gone [4]. That is about what the month's other 31 hacked entities lost between them on Immunefi's totals [3]. Among them were Safe-related user losses near $7.8 million [13], about $6 million from D'CENT's app wallet between September 15 and 20 [14] and roughly $6 million at the betting platform Duelbits on the day Bitget was hit [15]. Take out the $270 million that Immunefi says an attacker returned [3] and the month comes to about $472 million [5]. Bitget's $387.5 million is about 82% of that [6]. The account does not report any recovery of Bitget's funds, and it still ranks September, net of returns, among the costliest months since 2023 [12].
The counter-case is self-custody, and Crowdfund Insider's account makes it directly: September's concentration, it argues, should not be read as reassurance for people holding their own keys [16]. Coinkite's Coldcard firmware, shipped from around March 2021, weakened seed generation [17]. Effective entropy fell toward roughly 40 bits on Mk2 and Mk3 devices and to about 72 bits on Mk4, Mk5 and Q models, against the 128 bits users thought they had [17]. Attackers began sweeping weak seeds offline on July 30 [18]. Researchers put confirmed losses above 1,700 BTC and total estimates near $130 million [19]. That is about 3.7 times what September's 31 smaller hacked entities lost combined [8], though it built up over a longer stretch.
I think the platform reading holds for September on the returns reported so far. Everything outside Bitget, the 24 hacked DeFi protocols included [4], comes to under a fifth of the net total [9]. The strongest evidence against treating self-custody as the safe alternative is Coldcard: a randomness bug in a device marketed to the most security-conscious holders [21]. The account's own conclusion is that custody arguments treating a hardware wallet as a finished answer keep losing to implementation details [22].
What to watch
- Whether Bitget reports recovering or freezing any of the $387.5 million, which would shrink its share of September's net losses and leave the month as a tail of small breaches.
- October tallies from Immunefi, PeckShield and CertiK: a month where the net loss sits in DeFi protocol code would undercut the platform reading.
- Revised Coldcard loss estimates, now above 1,700 BTC confirmed with some upper bounds above 2,000 BTC.