Crypto Hacks Surge in September Thanks to Bitget and Liquid
Bitget and Liquid Network together accounted for most of the $766 million in September losses. The investigation points to a zero-day and highlights the pressure on exchanges under MiCA.

Key Takeaways
- Crypto hack losses rose to $766.49 million in September, 462% more than in August.
- Bitget and Liquid Network together accounted for about $707 million, or roughly 92% of the monthly total.
- SlowMist said the Bitget breach had already started on August 31 through a zero-day in third-party software.
Crypto hack losses climbed to $766.49 million (€675 million) in September. That was an increase of about 462% from the $136.3 million (€120 million) in August. That made September the worst month of 2026 so far, mainly because of two major incidents at Bitget and Liquid Network.
Two Incidents Dominate
According to PeckShield, Bitget lost about $387 million (€341 million). Liquid Network came in at around $320 million (€282 million), although a large part of that was later returned by the people behind the attack, who said they were white hats.
Together, those two incidents accounted for about $707 million (€623 million), or roughly 92% of the monthly total. The other 53 hacks added up to another $59 million (€52 million). That pushed September well past April, when losses of $646.89 million (€570 million) had already been the highest monthly total of 2026.
PeckShield also counted 55 major hacks in September, more than the 50 in August. That made it not just an expensive month, but also a busy one for the crypto market.
Bitget Investigates Attack
Bitget brought in blockchain security firm SlowMist to investigate the theft from its hot wallets. According to the report, which was current as of September 29, the breach had already started weeks before any funds were drained.
The first malicious activity dates back to August 31. An attacker exploited a zero-day in a third-party security product and used it to gain higher privileges. Researchers also found a modified withdrawal tool among deleted files.
SlowMist did not name a culprit. Bitget CEO Gracy Chen had earlier pointed to suspected North Korean hackers.
The aftermath of the attack was also still visible: part of the loot was later moved through Zcash to make the money flow harder to track.
Why This Matters
The numbers show how much damage security breaches at crypto exchanges can still cause, even at firms with mature infrastructure. For European crypto investors, that is especially relevant because MiCA sets stricter rules for governance, capital, internal controls, and cybersecurity. That puts even more pressure on platforms to keep their security in order.