September 2026: The Approval Layer Was Exploited

Share this article:

Crypto lost $742.0M across 33 incidents in September 2026, almost three times August's $255.5M and the biggest month of the year so far. Bitget's $387M hack and Liquid Network's $320M exploit account for about 95% of that, with the other 31 incidents adding up to $35.0M.

In August, the prices going into contracts were wrong. In September, attackers went after the systems that approve transactions in the first place.

Here's the month in security 馃憞

September 2026 losses by category

CategoryLossIncidents
Private key / hot-wallet compromise~$396.02M6
Bridge and cross-chain (unbacked mints, bridge logic)~$326.05M5
Malicious governance protocol~$9.30M2
Oracle / price manipulation~$4.28M4
Social engineering (impersonation)~$2.08M1
Access control~$1.91M5
Token and share accounting~$1.89M3
Protocol logic (swap, reward)~$0.45M6
Input validation~$0.05M1
Total (Sep 1 to 30)~$742.0M33

Source: DefiLlama

Hacks of the month

Bitget, ~$387M (Sep 24). The attacker used a zero-day in a third-party security product to get inside Bitget's network, then wrote forged withdrawal requests straight into the wallet backend, which Bitget's signing system approved as normal. Over almost three hours, 26 transfers drained hot and warm wallets across XRPL, Ethereum, Zcash, Tron, and several EVM chains. Bitget says its $464M user protection fund will cover the loss, and North Korea is the suspected attacker.

Source | Hypernative 路 BlockSec 路 Fortune 路 Bitget

Liquid Network, ~$320M (Sep 6). A bug in the cache Liquid's nodes used to skip re-checking range proofs, there since 2016, let two different inputs produce the same cache key. The attacker used that to get an invalid proof treated as already verified, minted 3,998.5 L-BTC with nothing behind it, and redeemed it for real BTC within 36 minutes. Self-described whitehats returned about 3,400 BTC the next day, and Blockstream has said it will cover the remaining gap in the peg.

Source | TRM Labs 路 The Crypto Times 路 Coinpaprika

Astroport and Drop, ~$9.3M (Sep 22). Both protocols had multisigs on their contracts, but Neutron's chain governance can reassign any contract's admin, and that power sits above anything an app sets up. The attacker bought enough NTRN to pass a proposal for roughly $20K, then migrated ten contracts to their own code and drained them in 24 minutes. The official postmortem puts the net loss at around $2.23M.

Source | Protos 路 GoPlus 路 Cosmos Hub Forum 路 Postmortem

Nostra, ~$3.5M (Sep 17). It followed the same pattern as Tectonic and Moonwell in August, where a thinly traded governance token was pumped and then used as collateral. NSTR's price went from about $0.006 to $49.50 on Starknet, and the attacker borrowed around $3.5M against it before Nostra paused the market.

Source | Shattered 路 The Crypto Times

Offchain: the breaches came through vendors.

Trezor's breach at its fulfillment provider ShipMonk grew to 81,000 customers, exposing names, phone numbers, and home addresses that ShipMonk had told Trezor were deleted.

Source | BleepingComputer

A few days later, attackers abused Brevo's SSO setup to take over 138 email marketing accounts and sent 347,000 Trezor users a fake security alert asking for their wallet backup phrases.

Source | SecurityWeek

Separately, a joint advisory from the FBI and allied agencies tied the WaterPlum fake job interview campaign to North Korea, after malicious coding tests infected more than 30,000 devices and moved $10.7M in crypto.

Source | Infosecurity Magazine

The pattern across the month.

Bitget's signer, Liquid's verification cache, and Neutron's governance all exist to decide whether something should go through, and in each case the attacker found a cheap way to get a yes. A few things worth adding to the review list:

Limit what can reach your signer. Bitget's attacker got in through a compromised third-party security product, took a high-level credential to an internal system, and used it to push forged withdrawals that the signer treated as legitimate. Every tool and credential with a path to signing belongs in the threat model.

Review the full stack, not just the contracts. Liquid's bug sat in node-level infrastructure, outside any smart contract, and survived a partial patch five weeks before the exploit.

Know what sits above your multisig. If a governance vote can migrate your contracts, the cost of buying that vote belongs in your threat model. DefiLlama has 8 governance attacks on record for 2026, compared with 1 in all of 2025.

Disclaimer

This report aggregates publicly reported information as of the publication date and may be revised as investigations evolve and post-mortems are released. Recommendations are general guidance. Verify against primary sources before acting on any specific claim.

About This Series

Quantstamp publishes the Security Beat monthly. We've conducted 1,300+ audits and secured $500B+ in digital assets across 250+ clients, including Ethereum Foundation, Aave, Polymarket, Ethena, Visa, OpenSea, Maker, Curve, Compound, and Lido. If you'd like to chat about anything security-related or request an audit, reach out.

Back
Quantstamp Announcements

August 2026: The Price Feed Was Exploited

Crypto lost $255.4M across 46 incidents in August 2026, roughly level with July's $254.4M, with more incidents than any month this year. June and July incidents were largely due to key compromises, but August shifted to price manipulation. Eleven oracle and price-manipulation incidents accounted for $135.87M, or 53% of the month. Two chains stopped producing blocks and rolled back state to undo the damage. Here's the month in security 馃憞

Read more
about August 2026: The Price Feed Was Exploited
Quantstamp Announcements

July Security Beat: Keys Over Code (Again?)

Crypto lost more than $240 million across 29 incidents in July 2026, up roughly 216% from June's $75.87M, even as the number of attacks fell from 40 to 29. For the second month running, the damage didn't come from clever contract exploits. The same failure class ran through Web2, from a $12.3M rail-industry ransom to a 1TB bank breach that started with one employee's email. Here's the month in security 馃憞

Read more
about July Security Beat: Keys Over Code (Again?)
Quantstamp Announcements

June Security Beat: Keys Over Code

$75.32M was lost across 32 crypto incidents in June, up from May's $59.52M. No coordinated campaign carried the month, but one targeted operation did. A targeted social-engineering attack against Humanity Protocol reached the keys behind the $H token and drained $32M, roughly 42% of every dollar lost in June. Quantstamp led the independent investigation and traced the tooling to a phishing campaign previously seen targeting macOS users. Offchain, a fresh npm supply chain wave hit Red Hat's packages on the first day of the month, and a PeopleSoft zero-day was exploited for two weeks before Oracle said a word. Here's the month in security 馃憞

Read more
about June Security Beat: Keys Over Code