Prices: CoinGecko

Security

Liquid and Bitget: what September 2026's two biggest crypto hacks teach ordinary users

A software bug drained Liquid's bitcoin reserve and a zero-day hit Bitget's hot wallets. What happened in September 2026 and how to reduce your own risk.

Intermediate7 min readPublished October 4, 20268 sources
On this page
  1. The numbers
  2. Liquid Network: a bug in the rules, not a stolen key
  3. Bitget: compromised through its own security tools
  4. What this means for regular users
  5. The bigger picture
  6. What to watch next

Key takeaways

  • PeckShield counted $766.49 million lost to crypto hacks in September 2026, and the Bitget and Liquid Network incidents made up roughly 92% of it.
  • Neither attack needed a stolen password or private key: Liquid was hit through a validation bug in its node software, and Bitget through zero-day flaws in third-party security products.
  • For users, the lessons are about custody: limit what you leave on any platform, understand what backs wrapped or bridged assets, and expect fake 'recovery' offers after big hacks.

September 2026 was the worst month for crypto theft so far this year, and two incidents did most of the damage. A bug let attackers drain nearly all the bitcoin backing Blockstream's Liquid Network, and a zero-day breach emptied part of Bitget's hot wallets. Neither depended on a user making a mistake, which is exactly why they are worth understanding.

The numbers

Security firm PeckShield counted 55 major hacks in September with $766.49 million in losses, up about 462% from August's $136.3 million, according to Incrypted's summary of the data. Bitget (about $388 million) and Liquid (about $320 million) together accounted for more than 90% of the month's total.

Liquid Network: a bug in the rules, not a stolen key

What happened

Liquid is a Bitcoin sidechain built by Blockstream and used by exchanges and traders to move bitcoin faster and more privately. You lock BTC with a federation of member firms and receive L-BTC on Liquid. To get BTC back, you burn L-BTC and the federation releases coins from its reserve after an 11-of-15 multisig approval, as TRM Labs explains.

Liquid hides transaction amounts, so each transaction carries a cryptographic "range proof" showing that no value was created from nothing. Checking these proofs is expensive, so the Elements software caches results. Chainalysis and TRM both describe a flaw in that cache: the attacker got valid proof data checked and stored, then submitted invalid data that the nodes treated as already verified.

On September 6 the attacker minted about 4,000 unbacked L-BTC, requested a withdrawal through an approved operator, and received roughly 3,996 BTC from the reserve. TRM reports the whole sequence took 36 minutes. Because the network software accepted the fake L-BTC as valid, the federation's signers approved the payout. Blockstream said no signing keys were compromised.

The unusual ending

Hours later, the attackers posted an on-chain message calling themselves "whitehats" and offered to return funds once the bug was patched. After the fix was deployed, about 3,400 BTC came back, roughly 85% of the total. About 598.5 BTC, worth around $47 million at the time, stayed with the attackers, who appear to be treating it as a bounty, according to TRM. Liquid later resumed transactions but kept peg-outs, the step that turns L-BTC back into BTC, disabled while recovery continued.

Bitget: compromised through its own security tools

What happened

Bitget says its systems detected unauthorized transfers from some hot wallets at 18:31 UTC on September 24. Hot wallets are online wallets an exchange uses to process withdrawals quickly. Bitget initially estimated losses at $351.6 million and said its cold wallets were untouched; later counts that included Zcash and TRON transfers put the figure near $387.5 million. Withdrawals were paused while deposits and trading continued.

Two independent investigations, by SlowMist and Google Cloud's Mandiant, found the entry point was two third-party security appliances. SlowMist traced the earliest malicious activity to August 31, more than three weeks before any money moved, when a zero-day flaw was used on one product. Mandiant described the attacker planting a web shell on one appliance, then moving to Bitget's production wallet server and deploying malicious packages, as BleepingComputer reported.

Chainalysis attributes the theft to North Korea-linked actors. It says the $387 million left in 23 transfers within about three hours, split across Ethereum, XRP Ledger, Zcash and Tron. Stolen XRP was routed through a cross-chain liquidity protocol and came out as bitcoin.

How customers were treated

Bitget said customer balances were not affected because the loss fell within its User Protection Fund, which held more than $464 million before the hack. CEO Gracy Chen told CNBC that the company had restored the fund to over $300 million from its own capital. Only about $1.1 million had been frozen, and she was "not expecting to recover a lot." Bitget also published a self-reported proof-of-reserves ratio of 131% from a September 29 snapshot.

What this means for regular users

Both attacks went after infrastructure rather than individual accounts. A strong password and two-factor login would not have stopped either one. What you control is how much of your money sits on infrastructure you cannot inspect.

  1. Keep exchange balances to what you actively use. Bitget says its customers' balances were untouched because it had a large reserve fund and chose to use it. Not every platform can or will. Long-term holdings are generally safer in a wallet you control; compare options in our hardware wallet comparisons.
  2. Know what backs a wrapped token. L-BTC, like any bridged or wrapped asset, is only as good as the reserve and the software guarding it. When most of Liquid's reserve was drained, getting the bitcoin back came down to on-chain negotiations with the attackers. Before you use a wrapped version of bitcoin or any other asset, ask who holds the underlying coins and how redemptions are approved.
  3. Read proof-of-reserves claims carefully. A self-reported reserve ratio is useful, but it is a snapshot the company prepares itself. Look for independent verification and for whether liabilities are included.
  4. Expect withdrawal pauses. Pausing withdrawals is a normal emergency step. Do not keep money you might urgently need on a single platform.
  5. Watch for follow-on scams. Large hacks are often followed by fake "compensation" sites and people offering to recover stolen funds for a fee. See our guide to recovery scams.

The bigger picture

TRM Labs notes that 2026 has seen a record number of hack incidents, with smaller typical losses than past years, punctuated by occasional very large thefts. September fits that pattern. It also shows two growing threats: attacks on supply-chain components, such as a vendor's security appliance, and on the verification logic of layers built on top of major blockchains.

What to watch next

  • Liquid's peg-out restart and whether the remaining 598.5 BTC is recovered, plus any changes to how Elements verifies proofs.
  • Bitget's final reports, including whether the third-party vendors are named so other firms using the same products can patch.
  • Laundering trails. Analytics firms are labeling addresses tied to both incidents, which can lead exchanges to freeze funds when they surface.

For a full overview of common threats and defenses, visit our security and scams hub and our guide to crypto risk management. Details are as of October 2026.

Frequently asked questions

Was Bitcoin itself hacked in the Liquid incident?

No. The flaw was in Elements, the software that runs the Liquid sidechain. The attacker created unbacked L-BTC on Liquid and redeemed it for real BTC held in the federation's reserve; the Bitcoin network worked normally.

Did Bitget customers lose money?

Bitget says user balances were not affected because it covered the loss from its User Protection Fund, which it later topped back up to more than $300 million with company capital.

Should I move my crypto off exchanges?

Many people keep only what they actively trade on an exchange and hold long-term savings in a wallet they control. That shifts the risk to your own key management, so set up backups carefully first.

Sources

  1. 2026's Biggest Hack To Date: Attackers Drained USD 319 Million in Bitcoin From Liquid Network, Then Returned 85% of Funds — TRM Labs
  2. How The $320M Exploit of Liquid Network Went Down — Chainalysis
  3. [SECURITY NOTICE] Bitget exchange hot wallets Incident — September 24, 2026 — Bitget
  4. Update On SlowMist and Mandiant Report — Bitget
  5. Bitget hacked via zero-day in third-party security products — BleepingComputer
  6. Bitget 'not expecting to recover a lot' from $388 million hack, CEO tells CNBC — CNBC
  7. How AI Helped Chainalysis Investigators Trace the $387 Million North Korea Stole from Bitget — Chainalysis
  8. Losses From Cryptocurrency Hacks Hit $766M in September — PeckShield — Incrypted

Published October 4, 2026 by The Crypto Guide editorial team. Educational content, not financial, legal or tax advice. Spot an error? Request a correction.