PI Global Investments
Alternative Investments

September’s $742 Million In Crypto Hacks Exposes The Limits Of Exchange And Hardware Custody


September 2026 was the worst month of the year for crypto theft, and it was not close. Immunefi reported that about $742 million was lost across 33 hacked entities, enough for the month alone to account for roughly a third of all money stolen in hacks so far in 2026.

About $270 million was later returned by an attacker. Twenty-four DeFi protocols were hit.

Bitget and Liquid Network together made up about 95 percent of the month’s losses, and DefiLlama ranked September the fifth-worst month for crypto hacks in the last decade.Other trackers put the damage slightly higher.

PeckShield counted 55 major incidents and $766.5 million stolen, a jump of roughly 462 percent from August’s $136.3 million.

CertiK recorded closer to 97 incidents and about $766 million to $768 million, with roughly $271 million returned or frozen.

The gap between firms is mostly a matter of what counts as a “major” incident.

On the two events that defined the month, they agree.

On September 24, Bitget lost about $387.5 million after attackers compromised infrastructure tied to its wallet system and pushed forged withdrawals across several networks.

It became the largest single theft of 2026.

Twelve days earlier, on September 6, Liquid Network lost about $319 million to $320 million when a flaw in how the network verified its bitcoin peg allowed unbacked L-BTC to be minted.

Parties claiming to be white hats later returned most of it—about $285 million, or roughly 85 percent.

Net of that return, September still ranks among the costliest months since 2023.

The rest of the ledger was smaller but pointed. Safe-related user losses ran near $7.8 million.

D’CENT’s app wallet lost about $6 million between September 15 and 20.

The betting platform Duelbits lost roughly $6 million on the same day as Bitget.

PeckShield also listed a front-run of an MEV bot, a payment processor bug, Astroport, Drop, Nostra Finance, and the Nomic nBTC bridge among the month’s top ten.

Concentration, not a flood of equally large breaches, produced the headline number.

That concentration should not be read as reassurance for self-custody.

The more damaging lesson of the summer arrived before September, and it did not require a hot wallet or a bridge.

Coinkite’s Coldcard hardware wallets shipped firmware, beginning around March 2021, that weakened seed generation.

On affected Mk2 and Mk3 devices, effective entropy fell toward roughly 40 bits; on later Mk4, Mk5, and Q models it was closer to 72 bits rather than the 128 bits users thought they had. From July 30, attackers swept weak seeds offline.

Researchers later put confirmed losses above 1,700 BTC and total estimates near $130 million, with some upper bounds above 2,000 BTC.

Updating the firmware does not repair a seed already created on vulnerable code.

Users had to move funds to a freshly generated seed.Trezor and Ledger illustrate different failure modes, not a clean bill of health.

In early September, a ShipMonk breach tied to Trezor order fulfillment exposed names, phone numbers, and shipping addresses for about 80,700 customers.

The devices themselves were not compromised, but that data is exactly what phishing and physical-threat campaigns use.

Ledger’s longer record—the 2020 e-commerce database leak, the 2023 Recover key-sharding controversy, and ongoing clone-device and support scams—shows how vendor account systems and user procedure fail even when the secure element holds.

A 2026 discussion of laser fault injection against the TROPIC01 chip, relevant to some newer Trezor designs, underlined a further limit: lab attacks with physical possession are a different threat from remote drainage, but they are not imaginary.

September’s $740 million-plus was mostly an exchange wallet and a peg-validation bug.

The Coldcard losses were a randomness bug in a device marketed for paranoia. The Trezor and Ledger issues were data exposure, supply chain, and social engineering. Custody arguments that treat “hardware wallet” as a finished answer keep losing to implementation details.





Source link

Related posts

OSC’s latest fund oversight report has a direct line to pension plan due diligence

D.William

The Institutional Pivot: Why 80% of Global Firms are Allocating to DeFi and Digital Assets in 2026| KuCoin

D.William

Singapore Hedge Funds Lean on Stability, VCC and ASEAN Access as Hong Kong Gains Momentum

D.William

Leave a Comment