Crypto Hacks Surge in September, Reaching $766 Million in Losses
September witnessed a dramatic spike in cryptocurrency hacks, with 55 major incidents resulting in a staggering $766.49 million in losses, according to data compiled by PeckShield. This figure represents a colossal 462% increase compared to August’s losses of $136.3 million, with two significant breaches accounting for the vast majority of the September total.
Bitget and Liquid Network Dominate September’s Losses
The Bitget incident, with losses estimated at approximately $387 million, and the Liquid Network theft of around $320 million (of which $285 million has since been recovered), have emerged as the largest and second-largest crypto thefts of the year to date. These events have surpassed previous major exploits such as those involving Drift and KelpDAO/LayerZero. When these two major incidents are excluded, the remaining 53 hacks from September collectively amounted to approximately $59 million, less than half of the total losses recorded in August.
Bitget Details Security Breach
Bitget confirmed that its security systems detected unauthorized transfers from portions of its hot wallets on September 24 at 18:31 UTC. CEO Gracy Chen explained that an attacker gained access to a backend system within the wallet infrastructure, manipulated transaction data, and deceived the authorization process to release funds. Chen clarified that a compromise of private keys was ruled out and that the exchange’s cold wallets, which hold the majority of its assets, remained unaffected. Bitget intends to cover the losses from its User Protection Fund, which currently holds over $464 million. “We will not run away from this, and every dollar will be accounted for,” Chen stated on X.
Liquid Network Suffers Major BTC Withdrawal
The loss at Liquid Network occurred earlier in the month, on September 6, when individuals identified as purported white-hat hackers withdrew approximately 4,000 BTC from the Liquid Federation wallet. The withdrawal utilized the SideSwap peg-out authorization key, although Liquid emphasized that the key itself was not compromised. In communications with Blockstream, the hacker indicated a willingness to return the funds once all nodes were patched. However, Ledger CTO Charles Guillemet expressed skepticism, noting that legitimate security researchers typically do not drain a bridge and then request on-chain contact.
North Korea-Linked Hackers Suspected in Laundering Efforts
In an update on September 29, SlowMist reported that hackers believed to be linked to North Korea are laundering the stolen Bitget funds. Their alleged method involves pairing CoW Protocol orders with Chainflip deposit addresses, converting the proceeds to Bitcoin, and then employing CoinJoin to obscure transaction trails. Cos, SlowMist’s founder, argued that anti-money laundering checks are struggling to keep pace with automated scripts. Chainflip is reportedly attempting to block these fund flows and has rejected at least one deposit, though it refunded the money rather than freezing it.
Other Notable September Exploits
The remaining eight entries in PeckShield’s top 10 hacks for September ranged from $3.15 million to $7.81 million. The largest of these was a front-running incident involving the MEV bot “yoink,” which resulted in the return of the stolen assets. The Payment Processor V2, specifically the LimitBreak contract at the center of a white-hat rescue on September 25, accounted for $6.6 million in losses, with $3.4 million recovered. In that operation, security researcher Quit successfully moved 23,155 NFTs valued at nearly $6 million out of exposed wallets, though a separate exploit path left 660 WETH unrecovered.



