Back to Blog10 min read
Security Reports

Blockchain Security Report: October 2026

September 2026 saw $766M in blockchain losses — the worst month of 2026. Bitget lost $387.5M to a supply chain attack, Liquid Network $318.7M to a cryptographic flaw. Here's the full breakdown.

Published: October 7, 2026
10 min read
4 views
✓ Written by blockchain developers·✓ Reviewed for technical accuracy
Blockchain Security Report: October 2026

Published October 8, 2026  ·  Coverage: September 1–30, 2026  ·  Author: Muhammad Asif  ·  9 min read  ·  Category: Security Reports

September 2026 was the worst month for blockchain security in 2026 — and it wasn't close. A single centralized exchange breach and a mainnet-level cryptographic flaw combined to push monthly losses past $766 million, dwarfing every previous month of the year. This report breaks down what happened, who lost what, and what every developer and protocol operator must act on now.

Audit Before You Deploy

Detect reentrancy, access control failures, oracle manipulation and more — free, in under 60 seconds.

Run a Free Smart Contract Audit →

Executive Summary — September 2026

$766MTotal Losses
~$496MNet Unrecovered
10+Named Incidents
$270MReturned / Frozen
+1,530%vs August ($47M)
#1Worst Month of 2026

Source: CertiK Hack3d September 2026 Report. Two incidents — Bitget ($387.5M) and Liquid Network ($318.7M) — account for 92% of all losses.

Losses by Attack Category

CategoryTotal Loss% of MonthKey Incident
Third-party / Supply Chain$387,500,00050.6%Bitget CEX
Invalid Signature / Cryptographic$324,697,15142.4%Liquid Network
Wallet Compromise$20,103,8392.6%D'CENT, Duelbits
Improper Permission Control$13,298,6931.7%Astroport, Nostra Finance
Reentrancy$2,248,1380.3%Various
Other / Unknown~$18,600,0002.4%ShopLink, unknowns

Notable Incidents — September 2026

1. Bitget (CEX) CRITICAL

$387.5M
September 24, 2026  ·  Centralized Exchange  ·  Ethereum / Multi-chain
Root causeAttacker exploited a zero-day vulnerability in a third-party security product to obtain high-level internal credentials, then injected fraudulent withdrawal commands into the wallet backend. Impact$387.5M drained across multiple chains. Largest single CEX hack of 2026. PreventionVendor security audits before integration. Multi-sig withdrawal authorization. Hardware security modules (HSM) for key management. Anomaly detection on withdrawal patterns.

2. Liquid Network (Blockstream) CRITICAL

$318.7M
September 6, 2026  ·  Mainnet / Layer 2  ·  Bitcoin Sidechain
Root causeA caching flaw in how nodes verified range proofs allowed a transaction to pass with unbacked output value — approximately 3,998.5 L-BTC created from nothing. Classified as invalid signature bypass. Impact$318.7M in L-BTC minted without backing. Exposed a fundamental gap in cryptographic proof validation at the node level. PreventionIndependent node implementation audits. Formal verification of range proof logic. Redundant validation layers before transaction finality.

3. Safe Wallet Users (rsETH Drain) HIGH

$7.8M
Mid-September 2026  ·  DeFi / Restaking  ·  Ethereum
Root causeRestaked ETH (rsETH) drained from Safe multi-sig wallets. Full post-mortem not published at time of writing. PreventionRestrict restaking protocol approvals. Regular Safe module audits. Monitor rsETH allowances.

4. D'CENT Wallet HIGH

$6.0M+
September 15–20, 2026  ·  Wallet / App  ·  Multi-chain
Root causeExposure in the D'CENT App Wallet affecting versions before 8.1.0. Hardware wallets were not affected. XRPL tracing suggests losses may exceed the reported $6M figure. PreventionKeep wallet apps updated. Use hardware wallets for large holdings. Segregate hot and cold storage.

5. Nostra Finance (Oracle Manipulation) HIGH

$3.5M
September 17, 2026  ·  DeFi Lending  ·  Starknet
Root causeAn attacker manipulated the NSTR token oracle price on the Starknet money market, allowing a single account to over-borrow against inflated collateral. PreventionUse Chainlink TWAP feeds instead of spot prices. Set collateral caps for illiquid tokens. Circuit breakers on abnormal borrow spikes.

6. Astroport (Governance Attack) MEDIUM

$4.4M
September 22, 2026  ·  DeFi / Governance  ·  Neutron (Cosmos)
Root causeGovernance proposal 9 on Neutron transferred admin rights. A linked wallet purchased NTRN tokens to swing the vote in the attacker's favor. No smart contract bug was exploited — the attack was purely governance-level. PreventionTimelock delays on admin transfer proposals. Minimum quorum requirements. On-chain vote monitoring alerts. Multi-sig on governance execution.

Month-over-Month Comparison

MetricAugust 2026September 2026Change
Total Losses$47M$766M+1,530%
Net Losses (after recovery)~$40M~$496M+1,140%
Named Incidents1210+Similar count
Largest Single Incident$14.2M (flash loan)$387.5M (Bitget)+2,628%
Top Attack VectorFlash loan + oracleThird-party supply chainShifted

Vulnerability Trends — October 2026 Outlook

VulnerabilityTrendNotes
Third-party / Supply chain attacks↑ RisingBitget proves infrastructure vendors are now the highest-value target. Expect more CEX and custodian supply chain attacks.
Governance manipulation↑ RisingAstroport attack required no code exploit — just token purchases. Low-liquidity governance tokens are now attack surfaces.
Oracle price manipulation→ StableNostra Finance repeats the same TWAP-vs-spot pattern seen monthly. Still the #1 fixable DeFi vulnerability.
Wallet app vulnerabilities↑ RisingD'CENT shows mobile wallet apps are soft targets. Hardware wallet security remained intact — the app layer is the gap.
Reentrancy↓ DecliningOnly $2.2M in September. ReentrancyGuard adoption is working. Still must be checked on every new contract.
Access control failures→ StableConsistently 15–20% of DeFi incidents. Missing modifiers on admin functions remain common.

Blockhertz AI Auditor — September 2026 Statistics

MetricValue
Contracts analyzed143
Average risk score71 / 100
Critical findings detected38
High severity findings127
Most common findingMissing access control modifier on privileged functions
Languages auditedSolidity (89%), Rust (7%), Move (3%), Vyper (1%)

Developer Security Checklist — October 2026

Pre-deployment Checklist

  • Audit all third-party dependencies and vendor integrations — not just your own contracts
  • Use Chainlink TWAP price feeds — never Uniswap V2/V3 spot price as the sole oracle
  • Apply OpenZeppelin AccessControl or onlyOwner to all admin, emergency, and privileged functions
  • Add governance timelocks (minimum 48 hours) on any proposal that transfers admin rights
  • Set minimum quorum thresholds to prevent low-liquidity token governance attacks
  • Use multi-sig (3-of-5 minimum) for treasury and withdrawal authorization — never single key
  • Implement circuit breakers on borrow amounts relative to collateral value changes
  • Run a Blockhertz AI pre-audit before submitting for manual review — catch obvious issues first
  • Segregate hot wallet balances — no hot wallet should hold more than operational liquidity
  • Implement anomaly detection on withdrawal volume and velocity

Resources

Sources & Methodology: Loss figures from CertiK Hack3d September 2026 Report. Incident details from CryptoTimes, Crypto Briefing, Blockonomi, and TradersUnion. Where sources disagree on figures, the CertiK figure is used as primary. Returned/frozen funds are subtracted from gross losses to produce net loss figures. This report covers September 1–30, 2026.

Related Articles

Resource Hub

Explore all articles →

Browse every guide on the Blockhertz blog

📚

Views

4

Read Time

10 min read

Likes

1

Published

Oct 7, 2026

SecurityBlockchain Security Reportoctober 2026solidityweb3cryptofinancefoundersrwablockhertz
SecurityBlockchain Security Reportoctober 2026solidityweb3cryptofinancefoundersrwablockhertz

SIGNAL THREAD

00 SIGNALS

NO SIGNALS YET — BE FIRST TO TRANSMIT

Muhammad Asif

Senior Blockchain Developer & Founder, Blockhertz

Blockchain developer and security engineer with 8+ years of experience. Founded Blockhertz in 2018 to build AI-powered tools for Web3 teams — smart contract auditing, architecture generation, gas optimization, and RWA tokenization platforms. Serving clients worldwide.