Live Prices
Markets

Crypto Hacks Surge 462% to $766M in September Led by Massive Bitget and Liquid Exploits

TheCryptoDesk Editorial · 2m read
Crypto Hacks Surge 462% to $766M in September Led by Massive Bitget and Liquid Exploits

Cryptocurrency security losses surged to $766.49 million across 55 major hacks in September, marking a 462% increase compared to August's $136.3 million, according to data from PeckShield.

Two Breaches Dominate Monthly Losses

The massive monthly total was overwhelmingly driven by two security incidents that became the largest and second-largest crypto thefts of the year to date, surpassing prior exploits involving Drift and KelpDAO/LayerZero. The largest incident hit cryptocurrency exchange Bitget, resulting in a $387 million loss after security systems flagged unauthorized transfers at 18:31 UTC on September 24. Bitget CEO Gracy Chen explained that an attacker breached a backend system in the exchange's wallet infrastructure, spoofing transaction data to bypass authorization. Chen confirmed that cold wallets were untouched and that losses would be fully covered by the exchange's User Protection Fund, which holds over $464 million.

The second major breach occurred on September 6, when perpetrators drained roughly 4,000 BTC valued at $320 million from the Liquid Network's Liquid Federation wallet using a SideSwap peg-out authorization key. Although $285 million was subsequently returned following on-chain negotiations, Ledger CTO Charles Guillemet expressed skepticism over the attacker's white-hat claims. Excluding these two massive breaches, the remaining 53 hacks in September totaled approximately $59 million, under half of August's total.

Key Takeaways

  • $766.49 million was lost across 55 hacks in September, up 462% from August's $136.3 million.
  • Bitget ($387 million) and Liquid Network ($320 million) accounted for the vast majority of stolen funds.
  • $285 million of the Liquid Network funds were returned, while Bitget will cover losses using its $464 million User Protection Fund.
  • Other top exploits ranged from $3.15 million to $7.81 million, including a $6.6 million breach of the LimitBreak Payment Processor V2 contract where researcher Quit rescued 23,155 NFTs worth nearly $6 million while 660WETH remained unrecovered.

Laundering Trails and Security Vulnerabilities

In a September 29 update, cybersecurity firm SlowMist reported that attackers are actively laundering the stolen Bitget funds. According to SlowMist founder Cos, hackers paired CoW Protocol orders with Chainflip deposit addresses to convert stolen assets into BTC, before using CoinJoin mixers to obscure movements. This aligns with recent reports where Chainalysis linked the $387M Bitget hack to North Korea. Although Chainflip attempted to reject illicit flows, it refunded at least one deposit rather than freezing it, demonstrating gaps in automated compliance while smart contract vulnerabilities continue to surface elsewhere, similar to when hackers exploited a third-party adapter on Aave.

Why It Matters

The extreme concentration of September's losses in two massive infrastructure exploits demonstrates that exchange backend systems and bridge authorization keys remain high-value targets for sophisticated threat groups. While corporate reserve funds and prompt security interventions successfully recovered or absorbed hundreds of millions in damage, rapid automated laundering techniques continue to outpace decentralized protocol compliance measures. Moving forward, crypto institutions face urgent pressure to enforce stricter API access controls and multi-signature safeguards to intercept automated data spoofing before funds enter mixing protocols.

Read next