TL;DR
Get hardware and tech essentials delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
Crypto security firm CertiK recorded 247 incidents and $1.26 billion in losses during the third quarter of 2026. Bitcoin rose 40% over the quarter, while September alone saw $768.5 million stolen—the largest monthly total reported for 2026. The figures come as industry experts warn that repeated exploits can damage trust beyond the direct financial losses.
Crypto security firm CertiK recorded 247 security incidents and $1.26 billion in losses during the third quarter of 2026, even as bitcoin rose 40% and attracted strong investor interest, according to figures reported by CoinDesk on Oct. 1. September accounted for $768.5 million of the losses, the largest monthly total of 2026 in the data, highlighting a widening contrast between the market rally and persistent security risks.
CertiK’s figures put year-to-date losses at $2.68 billion. September had 99 reported incidents, the highest monthly incident count since February 2025, as well as the year’s largest monthly loss total. The data cover incidents categorized as crypto security events; the source report does not provide a breakdown of the full $1.26 billion by exploit type, platform or recovery outcome.
Bitcoin closed the quarter up 40%, outperforming major assets, while investors put billions of dollars into exchange-traded funds tied to bitcoin and other tokens, CoinDesk reported. Some altcoins gained even more. Those market figures describe a separate trend from the security data: strong asset prices and fund inflows do not establish that crypto platforms or protocols are safe from attacks.
Nicolai Sondergaard, a senior research analyst at Nansen, told CoinDesk that the reputational damage may exceed the direct losses. He said repeated exploits can reinforce concerns about fragile infrastructure, potentially slowing institutional adoption and increasing scrutiny from regulators and custodians. Sondergaard added that many institutions use regulated investment products rather than interacting directly with decentralized finance protocols.
Security Risks Shadow the Rally
The quarter’s figures put the security problem alongside a period of strong market performance. The losses are smaller than the capital flowing into crypto ETFs, according to Sondergaard, but he warned that direct comparisons do not capture the potential cost to trust and adoption. Investors who gain exposure through regulated products may still be affected by broader concerns about the reliability of crypto infrastructure.
Insurance coverage offers a limited buffer against those risks. CoinGecko’s State of Crypto Security Report 2026, released in August, put on-chain crypto insurance capacity at $130.2 million, down 20.2% from $163 million the previous year. That capacity is not a measure of how much every affected user will recover, and the source material does not say what proportion of Q3 losses was insured or reimbursed.
As an affiliate, we earn on qualifying purchases.
Quarterly Gains, Persistent Exploits
The report describes two developments unfolding at once: bitcoin’s 40% quarterly gain and continuing losses from hacks and exploits. CoinDesk said Treasury yields had climbed to levels not seen in more than two decades during the quarter, while crypto investment products received billions of dollars. These details provide market context, but the supplied report does not establish that the rally caused the security incidents or that the incidents affected bitcoin’s price.
Security concerns were not limited to the incidents counted in the quarterly total. CertiK said on X that September’s figures showed how quickly the threat landscape could shift and called for security across every layer. Separately, Oliver Carding, head of marketing at Tesseract Group, told CoinDesk that AI tools could speed up the search for smart-contract weaknesses. Security firm Blockaid expects incidents involving AI agents, with prompt injection—hidden instructions designed to mislead an agent—identified as a likely attack route. These are warnings about emerging risks, not confirmation that AI caused the reported Q3 losses.
“September was a stark reminder of how quickly the threat landscape can shift.”
— CertiK, in a post on X
As an affiliate, we earn on qualifying purchases.
What the Loss Figures Cannot Show
The report does not identify the incidents behind the full $1.26 billion total, say how the losses were calculated, or explain how much was later recovered. It also does not provide a detailed comparison with earlier quarters, so the total alone cannot establish how Q3 security risk changed over time. The count and loss figures are attributed to CertiK, rather than independently verified in the supplied material.
It is also unclear how many incidents involved decentralized finance protocols, centralized services, individual users or other types of systems. The cited comments about institutional caution and AI-related threats are expert assessments, not measurements of their effect on adoption or proof that AI contributed to the quarter’s losses. CoinGecko’s insurance capacity figure does not show how much coverage was available for specific incidents.
crypto wallet with biometric security
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Further Incident and Insurance Data
The immediate next step for readers seeking a fuller picture is more detailed reporting on the incidents: their targets, causes, affected users, and any funds recovered. October’s security totals will show whether September’s spike continued, but the supplied report gives no forecast or date for the next CertiK update.
Further disclosures from security firms, affected platforms and insurers could clarify which vulnerabilities drove losses and how much protection victims had. For now, the reported quarter shows that market gains and security exposure coexisted; the data do not establish what the next quarter’s prices or incident totals will be.
cold storage cryptocurrency wallet
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
How much did crypto lose to hacks and security incidents in Q3 2026?
CertiK data cited by CoinDesk put losses at $1.26 billion across 247 incidents in the third quarter of 2026.
How much was stolen in September?
The report said $768.5 million was stolen in September, the largest monthly loss total of 2026 in the figures it cited. It also recorded 99 incidents that month.
How did bitcoin perform during the quarter?
Bitcoin closed the third quarter up 40%, according to the CoinDesk report. The market gain does not indicate that crypto platforms or protocols were secure.
Were the Q3 losses caused by artificial intelligence?
The source report does not say that AI caused the reported losses. Experts raised concerns that AI tools could speed up vulnerability discovery and create risks for AI agents, but these are warnings about potential threats.
How much on-chain crypto insurance was available?
CoinGecko’s 2026 security report put on-chain crypto insurance capacity at $130.2 million, down 20.2% from $163 million the previous year. That figure does not state how much of the Q3 losses was insured or recovered.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
