
CertiK: Q3 crypto security losses hit $1.26B, led by Bitget’s ~$388M hack
The Bitget incident made up about 31% of the quarter’s losses, concentrating Q3 risk in a single exchange event.
Crypto security losses totaled $1.26 billion in Q3 2026 across 247 incidents, up 53.9% from Q2, based on CertiK’s tracking. A roughly $387.5 million to $388 million Bitget hack accounted for about 31% of the quarter’s losses, skewing the quarter toward exchange-specific risk.
Q3 Losses Hit $1.26B as Bitget’s ~$388M Hack Dominates CertiK’s Ledger
CertiK’s Q3 2026 tally put crypto security losses at $1.26 billion across 247 incidents. That is up 53.9% from Q2’s $819.4 million. Incident count rose about 13% quarter-over-quarter, from 219 to 247.
The quarter’s profile was not “lots of medium-sized failures.” It was one outsized venue event. CertiK pegged the Bitget hack at about $387.5 million, also referenced as $388 million, and about 31% of total Q3 losses under CertiK’s methodology. The rounding gap is unresolved in the data provided, but the concentration point stands.
The rest of the top-of-book incidents show the risk surface was still broad, just not evenly distributed. CertiK listed Liquid Network’s $319 million exploit on Sept. 6 as the second-largest Q3 incident. It also ranked a $120 million Tectonic incident and a $112.7 million Coldcard theft among the quarter’s largest events.
For traders, that mix matters. Exchange hot-wallet failure, protocol exploit risk, and custody or device theft do not propagate the same way through liquidity, spreads, and venue behavior. Treating “security losses” as one bucket is how you miss where the next dislocation actually shows up.
September’s $769M Gross vs. $495.3M Adjusted: Recovery Math and Exploit-Heavy Mix
September did most of the quarter’s damage in headline terms. CertiK recorded roughly $769 million in losses across 99 security incidents for the month.
The recovery math changed the realized number. About $273 million was frozen or returned, leaving adjusted losses of $495.3 million. That gap is not cosmetic. It is the difference between a one-way hit to market confidence and a situation where post-incident clawbacks can stabilize sentiment and reduce forced selling pressure tied to stolen inventory.
The month was also exploit-dominant. Across 58 incidents, exploits accounted for $734 million, or nearly 96% of September’s losses. That composition matters because exploit-heavy months tend to produce faster second-order effects: emergency pauses, rushed patches, and liquidity fragmentation as venues and protocols tighten controls.
Bitget’s own description of the Sept. 24 incident points to a specific operational failure mode. Bitget said it detected unauthorized transfers from some hot wallets and suspended withdrawals. It also said attackers exploited a vulnerability in a third-party security product to obtain internal credentials and forge withdrawal commands.
The missing piece is the identity and technical detail of that third-party product. No vendor name, vulnerability ID, or write-up is included here. Until that is disclosed, traders cannot easily map whether the same tooling is a shared dependency across other venues, or a Bitget-specific integration problem.
How I’d Translate This Into Counterparty Risk Checks This Week
The threshold that matters is whether Bitget’s incident stays a one-off in CertiK’s Q3 distribution, or whether follow-on disclosures reveal a shared third-party security dependency across multiple exchanges. If the vendor and vulnerability details land and they are widely deployed, the risk shifts from “venue-specific operational failure” to “stack-level single point of failure,” and the market will price that differently.
The real test is whether September’s $273 million frozen or returned figure grows meaningfully with additional recovery updates. If adjusted losses keep compressing versus headline losses, this starts to look more like a sentiment catalyst than a structural drain on liquidity. If recoveries stall and withdrawal policy changes persist after Sept. 24, the practical impact is tighter venue risk limits and more fragmented liquidity where it matters most: on the exchanges traders rely on for execution.