Nearly $2.7 billion has been stolen from crypto platforms in the first nine months of 2026, according to blockchain security firm CertiK. The record figure, partly attributed to state-sponsored actors such as North Korea, highlights an alarming concentration of losses on a handful of major incidents.
🔑 Key takeaways
- $2.68 billion in gross losses between January and September 2026
- 658 security incidents recorded, with an average loss of $4.1 million
- The five largest hacks account for 59% of the total value stolen
- North Korea is linked to more than $1 billion in crypto thefts in 2026
- 88% of stolen funds came from platforms that had completed a security audit
2026 losses dominated by a handful of mega-hacks
CertiK’s report puts gross losses at $2.68 billion across 658 documented security incidents between January and September 2026. After deducting $420.4 million in frozen or recovered funds, the net figure stands at roughly $2.26 billion. The average loss per incident is $4.1 million, though this average obscures the highly skewed distribution of damage across the year.
The five largest attacks of the year – Bitget, Liquid Network, KelpDAO, Drift Protocol and an unidentified victim – together account for $1.57 billion, nearly 59% of all gross losses. This concentration shows how a single breach at a major exchange or protocol can single-handedly reshape the sector’s annual damage tally.
| Rank | Platform | Date | Losses ($M) |
|---|---|---|---|
| 1 | Bitget | Sept. 2026 | 351.6 – 387.5 |
| 2 | Liquid Network | Sept. 2026 | 318.7 |
| 3 | KelpDAO | April 2026 | 291.3 |
| 4 | Drift Protocol | April 2026 | 285.3 |
| 5 | Unidentified victim | 2026 | 284.8 |
“Crypto firms and users have lost nearly $2.7 billion to security incidents in the first nine months of 2026.”
CertiK, 2026 Security Report

September 2026: a black month for exchanges
September 2026 became the costliest month of the year, with roughly $766.5 million in losses, surpassing the previous record set in April ($651.3 million). The surge was almost entirely driven by two events: the Bitget hack and the Liquid Network breach, which together exceed $700 million.
The Bitget hack occurred on September 24 and was detected at 18:31 UTC through unauthorized transfers. The exchange immediately suspended withdrawals. Estimates diverge: $387.5 million according to CertiK, against $351.6 million per Bitget’s own disclosure. The platform’s User Protection Fund, holding more than $464 million, fully covers the loss. The native BGB token dropped about 5% after the announcement. Arkham Intelligence noted that “funds from several Bitget-labelled wallets on multiple blockchains were consolidated into a single address.” The attacker rushed to buy ether on Arbitrum, briefly pushing the WETH/USDC pool price to $2,870.
“The User Protection Fund, which holds more than $464 million, covers the entire loss.”
Gracy Chen, CEO of Bitget
North Korea: the dominant actor in crypto theft
Attacks attributed to North Korea remain a structural driver of the crisis. According to blockchain analytics firm Elliptic, the value stolen in attacks it links to Pyongyang has exceeded $1 billion in 2026 across more than 51 suspected incidents. In the first half, TRM Labs reported that North Korea-linked actors accounted for about $643 million, or 66% of stolen funds. The bulk came from the April attacks on Drift Protocol and KelpDAO.
Elliptic also estimates that North Korea has stolen more than $6 billion in crypto since 2017, funds Western governments believe are used to finance nuclear weapons and ballistic missile programs. The Lazarus Group was sanctioned by the U.S. Treasury in 2019, and the FBI formally attributed the Bybit hack of February 2025 – roughly $1.46 billion, the largest confirmed crypto heist to date – to North Korea. Elliptic further assesses the Bitget breach as “highly likely” to be North Korean, citing shared money-laundering patterns and infrastructure.
A surge of smaller incidents beyond the headlines
Beyond the mega-hacks, the incident count keeps breaking records. In August 2026, 50 distinct hacks were recorded, a monthly high. Total losses for the month nonetheless fell 49.5% from July to $136.3 million. The average loss per incident in August dropped to $2.7 million, versus $7.5 million in the second quarter.
According to TRM Labs, a “typical” hack now generates about $219,000 in losses. Of the 207 first-half incidents, 125 targeted smart contracts but represented only a small share of the value stolen. Conversely, the 15% of infrastructure compromises accounted for 76% of total value stolen. A CoinGecko report published in August adds a troubling dimension: 88% of stolen funds and about 60% of affected platforms had completed an independent security audit. Attackers are increasingly targeting gaps that traditional audits fail to cover.
Market impact and historical context
Market consequences have been mixed. After the KelpDAO hack in April, total value locked (TVL) in DeFi dropped by roughly $13 billion as users withdrew liquidity from LayerZero-related protocols. BGB’s 5% decline in September reflected investor nervousness, but the broader market remained stable, with traders treating the incident as Bitget-specific rather than systemic.
These events fit a longer pattern. In February 2025, roughly $1.46 billion was stolen from Bybit – the largest confirmed crypto heist on record. In 2022, the Ronin bridge lost $620 million (linked to Lazarus), and in 2021, Poly Network suffered a $611 million theft. The recurrence of mega-hacks confirms the persistent threat that state-sponsored groups pose to the crypto ecosystem.
| Date | Platform | Losses ($M) | Attribution |
|---|---|---|---|
| Feb. 2025 | Bybit | 1,460 | North Korea (FBI) |
| 2022 | Ronin Bridge | 620 | Lazarus |
| 2021 | Poly Network | 611 | Unconfirmed |
| Sept. 2026 | Bitget | 351.6 – 387.5 | North Korea (suspected) |
| Sept. 2026 | Liquid Network | 318.7 | Under investigation |
Conclusion: concentration meets dispersion
The first nine months of 2026 confirm two contradictory trends. On one side, state-sponsored mega-hacks concentrate the bulk of the damage: a handful of infrastructure compromises can move the needle by hundreds of millions. On the other, the sheer number of incidents keeps rising, pointing to a diffuse erosion of security across the less mature layers of the ecosystem – DEXs, bridges, Layer-2s and emerging DeFi protocols.
For investors and protocols, the lesson is harsh: traditional audits are no longer sufficient, and the concentration of capital on a few platforms creates a systemic risk that transcends any single project. If the current trajectory holds, 2026 could close above $3 billion in total losses, surpassing the previous record set in 2022.
Sources
This article is for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

