The two incidents accounted for more than half of the total revenue of $1.26 billion in the third quarter

According to CertiK, cryptocurrency-related cybersecurity incidents caused $1.26 billion in losses across 247 separate events in Q3 2026, a 53.9% increase from the $819.4 million recorded in Q2.

10/5/20264 min read

The severity level has increased

The comparative headline shows losses increased 53.9% compared to the previous quarter. The number of incidents increased by approximately 13%, from 219 to 247. These two figures describe two different phenomena. If the attacks had simply become more common, then losses and the number of incidents would have increased together. Instead, the average loss per incident increased from approximately $3.7 million in Q2 to approximately $5.1 million in Q3, and even that figure doesn't fully reflect the discrepancy.

Bitget lost $387.5 million and Liquid Network lost approximately $320 million, totaling around $707 million. That's about 56% of the total losses this quarter, caused by two of the 247 incidents. Excluding those two incidents, the remaining 245 incidents caused approximately $553 million, averaging around $2.3 million per incident, which is lower than the Q2 average.

Therefore, the accurate assessment is not that cryptocurrency security deteriorated broadly in Q3. It is noteworthy that two serious incidents occurred in a quarter that was generally unremarkable by this year's standards. Total quarterly losses in the industry are largely caused by rare events, and the graph of these measures the number of major incidents that occur rather than the average level of process security.

Not smart contract logic

These two quarterly incidents stemmed from different attack surfaces, and neither was a typical DeFi vulnerability exploitation. Bitget is a centralized exchange, and the breach targeted the hot wallet and withdrawal infrastructure, where customer funds are stored and accessed. It was a custodial and operational security flaw, not a protocol design error.

Liquid Network's damage stemmed from a stability vulnerability in Elements, the open-source software underlying Blockstream's Bitcoin subchain. No keys were stolen and no signatures were forged. The consortium allowed a seemingly legitimate price-pegging transaction because the converted L-BTC was generated through a range-bias-protection error. The system performed exactly what it was designed to do, for tokens that should never have existed.

That pattern continued until 2026. The Coldcard software vulnerability, where the random number generator switched to a deterministic function and allowed the systematic theft of approximately 1,806 BTC worth about $143.9 million, was a hardware software flaw. BounceBit's losses stemmed from a validation error in the now-defunct Evmos system. The Harmony attack generated over 3 trillion unauthorized tokens through a validation vulnerability. Cronos lost $120.4 million due to price manipulation of collateral for a low-volume token, and Drift lost $295.4 million in April due to an attacker listing a worthless token as collateral at an artificially inflated price.

The smart contract audit failed to detect most of these instances. Software noise, proof of the correctness of the consensus mechanism, exchange withdrawal infrastructure, and collateral listing policies are all different areas from those examined in Solidity, and the largest losses in 2026 stemmed from all four of these areas.

The safety net is shrinking while losses are increasing

CoinGecko's Cryptocurrency Security Report, published at the end of August, shows that total on-chain cryptocurrency insurance capacity reached only $130.2 million, a 20.2% decrease from $163 million a year earlier. Compared to total losses year-to-date of $2.68 billion, the insurance coverage represents less than 5% of the losses in a year. This figure is also less than one-third of the cost of the Bitget hack.

The key is the direction the problem is heading. Insurability decreases by 20% while losses increase, which happens when insurers conclude that the risk cannot be priced at a premium anyone is willing to pay. A market where coverage shrinks while the number of claims increases is not a market seeking equilibrium. It's a market where providers are withdrawing capital.

For users, this means that the actual remedy after a loss occurs is whatever the affected protocol chooses to provide, which the Drift case shows could be just a cent per dollar after six months.

Assessment and Conclusion

CertiK reported 99 incidents in September with total losses of $768.5 million. PeckShield reported approximately $766 million from 55 major cyberattacks in the same month. The total losses are nearly the same, while the number of incidents differs by almost half, because these companies apply different thresholds to define what constitutes an incident. Anyone comparing the number of incidents between different sources is comparing definitions, not facts.

Cronos validators undone 10,961 blocks and reversed $111.2 million of the $120.4 million stolen from the Tectonic attack—approximately 92%—in just hours. The Liquid Network attacker left a message on the blockchain claiming to be a whitehat and negotiating to return the majority of the funds. Approximately 82% of the Bitcoin stolen in the Coldcard attack was never transferred from its original addresses. Drift's recovery fund opened at $3.11 million against $295.4 million in verified losses.

These results range from near-total recovery to near-total loss, and the headline figures treat them all the same. Quarterly reports on total stolen funds, without net figures after recovery, are merely a measure of how much was taken, not how much was lost. For an industry where security reputation is shaped by these reports, it's a significant blunder in accounting practices.

Disclaimer: The content in this article is for informational, research, data analysis, and reference purposes only regarding the cryptocurrency market. All opinions, assessments, forecasts, or opinions reflect the author's perspective at the time of publication and do not constitute investment advice, solicitations for buying or selling, trading recommendations, advertising, marketing, or promotion of any financial products, services, or cryptocurrencies. Mentions of projects, tokens, protocols, exchanges, wallets, or cryptocurrency service providers (CASPs) are for research, analysis, or informational purposes only and should not be construed as endorsements, recommendations, or guarantees in any way. HCCVenture does not broker, advertise, market, promote, or connect users in Vietnam with any cryptocurrency services from CASPs. HCCVenture does not accept asset custody, investment mandates, manage assets, or execute transactions on behalf of clients. All investment decisions are made entirely through the reader's own research (DYOR), evaluation, and responsibility; HCCVenture is not liable for any losses or damages arising from the use of or reliance on the information presented in this article.

Compiled and analyzed by HCCVenture

Join our information channels: https://link3.to/holdcoincventure

Explore HCCVenture group

HCCVENTURE QUANT JSCO

© 2026 HCCVENTURE. ALL COPYRIGHTS RESERVED.

Connect with us

Popular content

Contact to us

Address: 8th Floor, Bach Dang Complex Building, 50 Bach Dang Street, Hai Chau Ward, Da Nang City, Vietnam.

Phone: 1900 1509

Gmail : sp_contact@hccventure.com

Disclaimer: The information on this website is for informational purposes only and should not be considered investment advice. We are not responsible for any risks or losses arising from investment decisions based on the content here.

TERMS AND CONDITIONS • CUSTOMER PROTECTION POLICY

ANALYTICAL AND NEWS CONTENT IS COMPILED AND PROVIDED BY EXPERTS IN THE FIELD OF DIGITAL FINANCE AND BLOCKCHAIN ​​BELONGING TO HCCVENTURE ORGANIZATION, INCLUDING OWNERSHIP OF THE CONTENT.

RESPONSIBLE FOR MANAGING ALL CONTENT AND ANALYSIS: HCCVENTURE FOUNDER - TRUONG MINH HUY

Read warnings about scams and phishing emails — REPORT A PROBLEM WITH OUR SITE.

HCCVENTURE Quantitative Data Joint Stock Company operates in the field of on-chain data analysis of crypto assets on the blockchain and provides market research reports on crypto assets. Check the company profile information (Business Registration Number: 0402354866) at www.masothue.com