
AI-generated summary
Cryptocurrency hacks increased in the third quarter of 2026, with $1.26 billion stolen according to CertiK, up 53.9% from the second quarter. September was the worst month with $768.5 million in losses, mainly due to code and infrastructure flaws. Despite this, bitcoin gained around 40% over the period.
Bullish rally, record loot. Hackers stole $1.26 billion in crypto in the third quarter of 2026. However, bitcoin gained around 40% over the same period. The bill has reached 2.68 billion since January.
September is the worst month of the year in gross terms with $768.5 million stolen. The Bitget hack alone accounts for almost a third of the quarter. At the same time, the sector's insurance capacity fell by 20% in one year.
Crypto hacks: 1.26 billion soar in the third quarter
CertiK recorded 247 incidents during the quarter, compared to 219 in the second. According to Cointelegraph, losses jumped by 53.9% compared to 819.4 million in the spring. September alone concentrated $768.5 million in losses in 99 incidents.
Code and infrastructure flaws do most of the damage. They represent 95% of the September bill ($733.8 million in 58 incidents). Phishing, on the other hand, peaks at 6.2 million.
CertiK specifies that $273.2 million was frozen or recovered. September's net losses therefore fall to 495.3 million. Adjusted losses for the quarter reached 869.6 million, or 10% more than in the second quarter. DefiLlama, for its part, has approximately $1.25 billion lost in 116 incidents. But its methodology is more restrictive.
Bitget and Liquid Network, more than 700 million between them
Bitget saw $387.5 million released from its hot wallets on September 24. The attacker first exploited a flaw in a security product from a third-party provider. He then obtained high-level internal credentials and then issued false takedown orders. Neither private keys nor cold storage were affected, according to general manager Gracy Chen.
Liquid Network opened the ball on September 6. The bug came from the rangeproof verification cache (the cryptographic proofs that validate confidential amounts). It allowed the creation of L-BTC without counterparty for approximately $319 million. But the hacker returned 3,400 BTC the next day. Around 600 BTC are still missing.
CertiK puts the August 30 attack against Tectonic, a lending protocol on Cronos, at $120 million. The hacker had inflated the price of the TONIC token almost 100 times in twenty minutes. Most other estimates, however, are around 75 million. Cronos validators then rewound the chain to the block before the attack. However, around 6 million had already flowed to Ethereum.
The Coldcard flaw dates back to a 2021 firmware update. This weakened the generation of seeds. The pirates took advantage of this between July 30 and August 6. They siphoned off 1,778 BTC from over 5,200 addresses, or $112.7 million according to CertiK. Galaxy Research also estimates that the loot could climb to 2,417 BTC with a fourth wave.
Bitcoin soars, insurance declines
Bitcoin gained around 40% over the quarter, its best performance since 2024. Conversely, the sector's insurance capacity fell to $130.2 million at the end of August. It still reached 163.2 million a year earlier. The figure comes from CoinGecko's 2026 Crypto Security Report.
This amount covers less than 5% of the 2.68 billion stolen since January. Compensation also follows the same slope. Insurers only paid out around $33 million between January 2025 and July 2026. This represents barely 0.9% of the $3.63 billion lost. Supply is also contracting. Five of the nine on-chain insurance protocols tracked by CoinGecko have closed or abandoned crypto coverage.
AI accelerates the hunt for vulnerabilities
Nicolai Sondergaard, analyst at Nansen, provided his diagnosis to CoinDesk. According to him, “repeated exploits reinforce the idea that crypto infrastructure remains operationally fragile”. Oliver Carding, from Tesseract Group, also points to another accelerator. AI tools now automate the search for flaws in smart contracts. This work used to take months for a seasoned engineer.
The list is already growing in October. NEAR Intents lost $3.8 million in user funds on October 1. The cause is a bug between the Omni deposit and withdrawal infrastructure and its smart contract. The protocol had however blocked $50 million linked to the Bitget hack a few days earlier. He finally promises a full refund.
AI outlook — possibilities, not facts
Exchange platforms will strengthen the security of their hot wallets and limit access to high-level internal identifiers.
Likely · Within weeks
The use of AI to detect vulnerabilities in smart contracts will become widespread among security auditors.
Very likely · Within months
On-chain insurance protocols will continue to reduce or abandon their crypto coverage in the face of increasing losses.
Likely · Within months

The Danish government announced on Monday the leak of the data of nearly 8.8 million people registered in the central population register, consulted illegally via access from a private company.

Near Intents has recovered all of the $3.8 million stolen in an attack on its cross-chain swap service, following a 48-hour ultimatum from its chief executive.

In its 2026 index published on September 23, Chainalysis ranks Brazil first in the world for crypto adoption, ahead of the United States. Latin American activity grew by 9.8%, driven by the massive use of stablecoins.

OpenAI fired three employees for sharing confidential information with a third-party organization. This case comes shortly after the cancellation of GPT-6.1 Astra.

The Ethereum Foundation launched zkAPI, a protocol for paying for AI services via Ethereum without tying requests to an identity or account, ensuring anonymity of transactions through zero-knowledge proofs.

The Base network (Layer 2 of Coinbase) has activated the Cobalt update. It introduces 'Validity Transactions' for private conditional orders and extends the B20 standard, enabling complex compliance management and on-chain administrative entries.