Crypto

Two Hacks Made Up Nine-Tenths of Crypto's Worst Month of the Year

September losses reached about $766 million. Lightning node software and a cross-chain protocol are now dealing with fresh incidents. Crypto lost about $766 million to hacks and exploits across 55 incidents in September, the worst month of …

Two Hacks Made Up Nine-Tenths of Crypto's Worst Month of the Year
Two Hacks Made Up Nine-Tenths of Crypto's Worst Month of the Year

September losses reached about $766 million. Lightning node software and a cross-chain protocol are now dealing with fresh incidents.

Crypto lost about $766 million to hacks and exploits across 55 incidents in September, the worst month of 2026 so far. The total is heavily concentrated: the Bitget exchange breach at $388 million and the Liquid Network exploit at $320 million together account for $708 million, or roughly 92% of the month's losses. Year-to-date losses stand at about $2.7 billion, with North Korea-linked groups responsible for more than $1 billion.

October has opened with warnings at the infrastructure layer.

Lightning nodes

Core Lightning, one of the main software implementations of Bitcoin's Lightning payment network, issued an urgent call on Friday for operators running version 26.06.7 or earlier to upgrade, citing reports that attackers are targeting unpatched nodes. Version 26.06.8, released Sept. 22, fixed several flaws, including a channel-closing bug that could cause an operator to lose funds through a penalty transaction.

The warning concerns node operators and custodial Lightning services. Bitcoin held on the main chain is not affected, and no losses or victim count have been disclosed.

NEAR Intents sets a deadline

At NEAR Intents, a cross-chain trading protocol recovering from a recent exploit, general manager Alex Shevchenko said the team has identified the attacker and set a 48-hour window for the funds to be returned. The tactic has worked before: a similar ultimatum preceded a partial recovery in an April incident at another protocol. NEAR's token rose 2.4% overnight to $4.92.

Bitget's recovery math

At Bitget, blockchain tracing so far has frozen about $840,000 of the stolen funds, or roughly 0.2% of the total. The exchange has restored its $300 million user protection fund and scheduled the final phase of its withdrawal reopening, covering remaining tokens, fiat and peer-to-peer trading, for Friday at 08:00 UTC.

A smaller incident rounds out the week: a third-party module built on Aave V3, known as FlashLoopAdapter, was drained of about 114 ether, worth roughly $305,000, from two Safe wallets. Aave's core protocol has not been reported as affected.

The pattern

The common thread is that losses are increasingly arriving through the edges of the system: exchange hot wallets, add-on modules, bridges and node software, rather than through base-layer blockchains. That shifts the risk assessment for investors from "is the chain secure" to "is everything built around it patched and audited."

What to watch: Whether funds return to NEAR Intents before the deadline expires around Oct. 4, and whether Bitget confirms full restoration of services. Both would offer rare evidence that pressure and tracing can recover meaningful sums.

More articles from FinancialMarkets.com