BlockBeats news, September 25 — As of now, 86 major security incidents have occurred in the crypto market in 2026. Including Bitget's newly disclosed preliminary loss of approximately $351.6 million, the publicly reported losses from major incidents this year have exceeded $2.3 billion. These include:
Bitget: approximately $351.6 million. Hackers breached key backend systems of the wallet service, forged transfer information, and moved assets across multiple chains; Bitget has suspended withdrawals and stated that its protection fund can cover the related losses.
Liquid Network: approximately $319 million. Attackers exploited a vulnerability in the Elements range proof verification cache to create approximately 4,000 uncollateralized LBTC, then swapped them out for BTC through the peg-out mechanism; 3,400 BTC was subsequently returned, and approximately 602 BTC remains unrepaid.
KelpDAO: approximately $292 million. Attackers compromised LayerZero-related infrastructure and forged cross-chain messages, minting 116,500 rsETH without underlying asset backing, then used them to borrow other real assets.
Drift Protocol: approximately $285 million. Attackers gained security council administrative privileges through social engineering and pre-signed transactions, added tokens with no real value as collateral, and used them to withdraw assets including USDC, SOL, and ETH.
A whale wallet: approximately $282 million. Attackers impersonated crypto hardware wallet customer service, used social engineering to obtain the seed phrase, stole 1,459 BTC and 2.05 million LTC, and quickly converted part of the funds into XMR.
Coldcard wallet vulnerability: approximately $114 million. Some firmware used insufficiently strong randomness when generating seed phrases, allowing attackers to reconstruct private keys offline without touching the hardware devices and transfer BTC from related addresses in bulk.

