Crypto hacks triggered more than $766 million in losses during the month of September, according to initial estimates from PeckShield and Certik. This is the heaviest toll of the year. However, it was revised to $772.4 million by Certik, with Bitget and Liquid Network taking the bulk of the damage.

In brief
- Crypto hacks caused $766 million in losses in September.
- Bitget and Liquid Network account for almost 92% of the initial balance sheet.
- Bitget now puts the allocated funds at $387.5 million.
- Liquid Network suffered a breach which allowed the fraudulent creation of L-BTC.
Two crypto hacks account for 92% of losses
Fifty-five major incidents were recorded by PeckShield for an initial amount of $766.49 million. CertiK, whose methodology brings together more events, counted around a hundred and estimated losses at nearly $768 million.
From now on, this total is brought to $772.4 million on the CertiK dashboard. This revision explains the difficulty of directly establishing a definitive assessment, particularly when new addresses or victims are identified. THE essential figures make it possible to measure the concentration of losses:
- Bitget represents $387.5 million in restricted funds;
- Liquid Network totals $318.7 million;
- These two incidents account for almost 92% of the initial toll;
- The other 53 attacks tracked by PeckShield amount to approximately $59 million;
- CertiK classifies $739.5 million as exploit losses.
September’s losses would therefore remain less than half of the $136.3 million recorded by PeckShield in August, without the balance sheet of Bitget and Liquid Network. This monthly record does not indicate a uniform explosion of attacks.
Bitget hack costs nearly $388 million
Bitget detected unauthorized transfers on September 24. The incident affected several wallets on Ethereum, other EVM-enabled networks, XRP Ledger, Zcash and Tron.
The exchange initially valued the funds involved at $351.6 million. He then raised this estimate to 387.5 million after incorporating new transactions. His cold wallets and private keys would not have been compromised.
According to Bitget, the hackers exploited a flaw in a third-party security product to obtain internal access credentials. They then allegedly falsified withdrawal orders in order to circumvent system controls.
The platform claims that its protection fund, with more than $464 million, will fully cover losses. “We will not run away from this situation, and every dollar will be counted”declared its general director, Gracy Chen. This coverage nevertheless remains a commitment of the company, the execution of which must be monitored.
Liquid reveals a flaw at the heart of the Bitcoin protocol
The Liquid Network incident occurred on September 6. A vulnerability in Elements, the software on which this Bitcoin sidechain is based, allowed the creation of approximately 3,998.5 L-BTC without corresponding bitcoins as collateral.
The flaw concerned the system responsible for verifying confidential crypto transactions. Thus, the hacker prepared several operations in order to deceive the validation cache, then used a malicious transaction to issue unauthorized L-BTC. The assets were then converted into native bitcoins through the network’s exit mechanism.
The value affected was approximately $318.7 million at the time of the attack. The author presented himself as a security researcher and promised to return the funds after the nodes were fixed. This qualification of “white hat” however, caused doubts, because no authorized audit provided for the withdrawal of several thousand bitcoins.
PeckShield estimates that about $285 million was ultimately returned. The gross amount of the incident nevertheless remains included in the monthly losses, before deduction of the funds recovered.
Crypto hacks weigh on the entire third quarter
Behind Bitget and Liquid, CertiK identifies several more limited incidents. Safe Wallet users lost approximately $7.8 million. D’CENT and Duelbits each suffered nearly $6 million in damages, while NEAR Intents reported a loss close to $3.9 million.
The third quarter thus totaled 1.27 billion dollars in losses, compared to 819.4 million in the previous quarter. The increase reached 54.4%. After taking into account the amounts frozen or returned, CertiK, however, reduces the adjusted losses for the quarter to approximately $869.6 million.
Technical exploits account for 95.7% of September damage. Compromises of private keys, wallets and phishing campaigns remain numerous, but their financial weight appears secondary to the two main attacks.
The final assessment may still evolve as recoveries and new victims are identified. Above all, September shows that a single failure in a central infrastructure can weigh more than several dozen attacks combined.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
