
September 2026 will go down as the darkest month in DeFi history. In just 30 days, attackers drained $768 million from two major protocols — a 462% spike compared to August. Total losses for 2026 now sit at $1.3 billion, and we still have three months left in the year.
If you're building or operating a protocol, this is not a story about other people's problems. It's a warning.
What Happened: Two Hacks, $768M Gone
Bitget Exchange — $351.6M (September 24, 2026)
At 18:31 UTC on September 24, Bitget — one of the world's largest crypto exchanges — began bleeding funds.
Funds were drained across 11 blockchains and 13 assets — XRP, ETH, USDT, and more — from 12 wallet addresses. Cold wallets were untouched. User balances were protected by Bitget's $300M+ Protection Fund. Bitget detected and contained the breach in 34 minutes, with full withdrawal restoration by October 2.
The lesson: Your security is only as strong as your weakest dependency. Every third-party vendor with credential-level access to your infrastructure is part of your attack surface.
Liquid Network — $320M (September 2026)
The second blow came from Blockstream's Liquid Network — a Bitcoin sidechain used for fast, confidential BTC transactions.
The attacker minted approximately 4,000 unbacked L-BTC, then used the legitimate peg-out mechanism to exchange them for real Bitcoin — draining ~95% of the protocol's reserves. The attacker later returned 3,400 BTC, suggesting possible white-hat intentions.
The most damning detail: The fix existed in the codebase. The patch had been written but never shipped. Nodes were running vulnerable code while the fix sat undeployed.
The lesson: An undeployed patch is not a fix. Proof verification and cryptographic cache logic need formal auditing — not just a code review.
2026 at a Glance: The Same Attacks, Over and Over
| Protocol | Date | Amount | Attack Type |
|---|---|---|---|
| Bitget | Sep 24 | $351.6M | Compromised third-party credentials |
| Liquid Network | Sep 2026 | $320M | Proof verification cache collision |
| KelpDAO | Apr 18 | $292M | Compromised RPC + bridge flaw |
| Drift Protocol | Apr 1 | $285M | Governance manipulation + oracle abuse |
| Truebit | Jan 8 | $26.2M | Integer overflow |
| 2026 Total | ~$1.3B |
The pattern is clear: access control failures, unpatched vulnerabilities, and third-party dependencies are the three vectors that keep winning. These aren't novel zero-days — they're known vulnerability classes that automated tools can detect before deployment.
What This Means for Your Protocol
- Have your proof verification and cryptographic implementations been audited? The Liquid Network had a known fix sitting undeployed. An audit process would have caught the gap.
- What third-party tools have privileged access to your infrastructure? Every vendor with credential-level access is a potential Bitget scenario.
- Are your integer boundaries checked? Truebit lost $26.2M to an integer overflow — one of the oldest vulnerabilities in the book.
- Do your oracle feeds have manipulation protections? Oracle abuse hit multiple protocols this year for a combined $300M+.
Audit Before You Ship
The Blockhertz AI Auditor scans your Solidity contracts for the exact vulnerability classes that dominated 2026's losses — in under 60 seconds.
Run a Free Audit →Resource Hub
Explore all articles →
Browse every guide on the Blockhertz blog
Explore Blockhertz
Views
5
Read Time
8 min read
Likes
0
Published
Oct 5, 2026
SIGNAL THREAD
NO SIGNALS YET — BE FIRST TO TRANSMIT
Muhammad Asif
Senior Blockchain Developer & Founder, Blockhertz
Blockchain developer and security engineer with 8+ years of experience. Founded Blockhertz in 2018 to build AI-powered tools for Web3 teams — smart contract auditing, architecture generation, gas optimization, and RWA tokenization platforms. Serving clients worldwide.