Q3 Crypto Security Breaches Exceed $1 Billion Following Bitget's $388M Attack

Q3 Crypto Security Breaches Exceed $1 Billion Following Bitget's $388M Attack

Third-quarter cryptocurrency security breaches totaled $1.26 billion across 247 separate incidents, with the month of September representing approximately $769 million in damages.

The third quarter of 2026 saw cryptocurrency security incident losses surge to $1.26 billion, with the majority of the damage stemming from a $387.5 million security breach at cryptocurrency exchange Bitget.

According to blockchain security firm CertiK's data, losses experienced a 53.9% quarter-over-quarter increase from the second quarter's $819.4 million, while security incidents grew approximately 13% from 219 incidents to 247.

Bitget's security breach represented roughly 31% of the third quarter's total losses, establishing itself as the largest single incident documented during the period according to CertiK's tracking methodology. The Liquid Network breach on Sept. 6, which resulted in $319 million in losses, came in second place, with Tectonic's $120 million incident and the Coldcard theft totaling $112.7 million following behind.

Largest crypto industry incidents in Q3 2026
Top crypto industry security incidents during Q3 2026 as documented by CertiK. Source: CertiK

September saw approximately $769 million in damages across 99 separate security incidents, as documented by CertiK. Approximately $273 million of these funds were either frozen or successfully returned, bringing the adjusted loss figure to $495.3 million. Exploit-based attacks were responsible for $734 million in damages across 58 separate incidents, representing nearly 96% of September's total losses.

On Sept. 24, Bitget identified unauthorized transfer activity originating from several of its hot wallet addresses and immediately halted withdrawal services. According to the company's statement, the attackers successfully leveraged a security flaw in a third-party security solution to gain access to internal authentication credentials, which they then used to create fraudulent withdrawal requests.