Invest1 publisher3 min readPublished
One Bitget breach supplied half of September's record $766 million in crypto hack losses
Crypto hacks drained $766.49 million in September, a 2026 monthly record, and $387.5 million came from one breach of Bitget's hot wallets. After the money returned from the Liquid Network exploit, that one exchange accounts for about 80% of what stayed stolen.
The Investor · Invest desk

What happened
- According to Cryptopolitan's tally, September's losses were 462% larger than August's.
- The Liquid Network exploit took $320 million, about $285 million of which was later returned, making it the year's second-largest hack after Bitget.
- Attackers got into Bitget's hot wallets with compromised wallet keys, the method behind the month's biggest losses.
- Stolen funds moved within hours and were mixed within days through DEX swaps, Tornado Cash and no-KYC exchanges, and some were swapped into Monero and shielded ZCash.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Protocol audits do not protect balances held on an exchange. For those funds, the questions are how the exchange guards its hot-wallet keys and whether it pays customers when keys leak.
- constraint September's dollar record tells you little about how widespread attacks are, because one breach decides whether the month is a record at all. Incident counts are the better measure of breadth.
- decision Gross hack tables overstate protocol damage when stolen funds come back. Anyone weighing exchange risk against protocol risk needs figures net of recoveries.
Netting out recoveries changes the split. On gross figures, according to Cryptopolitan's tally, Bitget was about 51% of September [4]. Take Liquid's returned $285 million [5] off the $766.49 million total [1] and about $481 million stayed stolen [2]. Bitget's $387.5 million [2] is roughly 80% of that [3]. Every other September incident combined comes to about $94 million net [12], so the exchange lost a little over four times as much as all of them together. The Gnosis safe funds also came back after the Yoink bot front-ran the attack [6]. That makes the true net total somewhat lower and Bitget's share somewhat higher.
The record itself rests on that breach. Without Bitget, September's gross losses come to about $379 million [5], short of the more than $648 million lost in April, when KelpDAO was hacked [4]. Bitget and Liquid together took $707.5 million, or 92% of the month [6]. The remaining $59 million or so [7] was spread across hacks that PeckShield data put at $3 million to $7 million each [7], and 13 exploits cleared $500,000 [13]. A 462% rise [3] implies August losses of about $136 million [8].
Incident counts show more breadth than the dollar totals do. Certik counted 99 security incidents in September [9], and its quarterly figures put both incidents and losses above the second quarter [10]. If the monthly and quarterly series line up, September alone was about 64% of the third quarter's $1.2 billion [9]. They may not line up exactly: the article's summary gives September as over $768 million [14], against $766.49 million in its body [1].
Stolen keys are an operational failure inside the exchange, and no audit of contract code reaches them [8]. The protocol side had failures of its own, with flaws in bridge, contract and minting logic still exploited, possibly with AI help, according to the report [11]. Either way the money moves within hours and is mixed within days [12]. The report does not say whether Bitget recovered any funds or covered customer balances from its own capital.
That gap decides who held the risk. If Bitget absorbed the loss, its depositors are exposed to the exchange's solvency. If it did not, the loss sat in their balances. Recovery is the third path. Bitget would need to get back about $294 million, or 76% of the theft [10], before its share of September's net losses fell below half. Liquid got back 89% of its own [11], leaving it a net loss of about $35 million [1].
I think the evidence supports the exchange-risk view for September, and supports it more strongly than an even split between exchanges and protocols would. The counter-case is that one month is one event. The report describes September's hacks as extremely varied, with a large share hitting Web3 infrastructure [15]. A large Bitget recovery, or a fourth quarter of protocol losses with no exchange breach, would put the weight back on the protocol side.
What to watch
- A Bitget statement on recovered funds, or on paying customers back from its own capital, would settle who carried September's largest loss.
- October totals from PeckShield and Certik: a month without a nine-figure breach would show whether the dollar trend holds up without one outsized event.