Crypto hacks caused $766.49 million in losses across 55 major incidents in September 2026, according to PeckShield, a roughly 462% increase from August's $136.3 million. The jump was driven almost entirely by two incidents that now rank as the largest crypto thefts of the year to date, surpassing the Drift and KelpDAO/LayerZero exploits that had previously topped the list.

The two incidents that reshaped the year's loss rankings

Bitget's hot wallet breach accounted for approximately $387 million, the largest single incident of the month and now the largest crypto hack of 2026 so far. As covered in detail when the incident broke, the exchange confirmed cold wallets remained untouched and committed the full loss amount to its $464 million User Protection Fund.

Liquid Network's incident followed closely behind at approximately $320 million, though $285 million of that was later returned. The Bitcoin sidechain operated by Blockstream saw purported white-hat hackers withdraw funds through a vulnerability in Elements, the software underpinning Liquid, before returning the bulk of the funds once Blockstream confirmed its bridge nodes had been patched.

Together, these two incidents alone account for approximately $707 million of September's $766.49 million total, meaning the remaining 53 hacks PeckShield tracked combined for roughly $59 million. That concentration shows how a handful of large, high-profile breaches can skew a monthly total far beyond the frequency of smaller ones, a trend that’s been seen in past months when one or two outsized events have repeatedly driven aggregate loss figures across the industry.

The mid-tier incidents and what connects several of them

An MEV bot known as "yoink" front-ran an active exploit transaction and extracted $7.81 million, later returned. This incident traced back to a Gnosis Safe wallet exploit on Ethereum, where an attacker exploited a flawed authorization check in a router contract to drain rsETH collateral, only for the MEV bot to intercept and redirect the stolen funds before the original attacker could claim them.

Duelbits, a gambling platform, lost approximately $7 million. A Payment Processor V2 exploit cost $6.6 million, with $3.4 million later returned. This incident connects directly to the Magic Eden vulnerability also reported in September, where old EVM marketplace approvals left hundreds of wallets exposed months after Magic Eden shut down its Ethereum NFT marketplace, with security researcher 0xQuit rescuing tens of thousands of NFTs before an attacker could reach them.

DCENT Wallet, Astroport, and the remaining incidents

DCENT Wallet, a hardware wallet provider, reported losses of $6.57 million. Astroport, a decentralized exchange, lost approximately $4.9 million. A protocol identified as Drop saw $4.4 million drained, while Nostra Finance, a lending protocol, lost $3.5 million. The Nomic nBTC Bridge, infrastructure designed to bring Bitcoin liquidity onto other chains, rounds out the top 10 with a $3.15 million loss.

Why the recovery rate matters as much as the loss total

A notable thread running through September's incidents is the share of funds recovered or returned. Of the roughly $766 million in gross losses, at least $288.4 million was returned across just three incidents: Liquid Network's $285 million, the yoink MEV bot's $7.81 million, and Payment Processor V2's $3.4 million.

Liquid Network's white-hat negotiation, conducted entirely through on-chain PGP-signed messages, and the MEV bot's interception of another attacker's exploit both represent outcomes where funds changed hands multiple times before settling with a party willing to return them, rather than a straightforward theft with no recovery path. This dynamic, while not guaranteed to repeat, meant September's net loss figure after recoveries sits meaningfully below the gross $766.49 million PeckShield reported, even though the headline figure captures only the initial loss before any return occurred.

September's total marks one of the more severe months for crypto security losses in 2026, driven overwhelmingly by the concentration of value in its two largest incidents rather than a broad increase in hack frequency across the sector.

MetaMask Staking Exits Validators after Security Incident | HODL FM NEWS
MetaMask disclosed an infrastructure compromise and is exiting affected Ethereum validators through Lido, with full withdrawals expected to take up to 45 days.
hodl-post-image

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.