Crypto suffered 247 security incidents in the third quarter and lost $1.26 billion, according to data from security firm CertiK, even as bitcoin closed its best quarterly run in years. The losses landed in the same three months that saw US spot bitcoin ETFs absorb billions in fresh inflows and BTC climb 40%.
Bitcoin ended September at $83,785, up 40% for the quarter, better than every major asset class while Treasury yields pushed to their highest levels in more than two decades. Investors poured billions into ETFs tied to BTC and other tokens over the period, and several altcoins rallied even harder. Analysts called it a fresh bull run. The security data tells a different story running underneath it. Losses for 2026 now stand at $2.68 billion with a full quarter still to play.
September was the worst month of the year
September alone recorded 99 incidents, the most since February 2025, and $768.5 million stolen. That is the largest monthly haul of 2026. CertiK, which publishes a rolling dashboard of exploited contracts, compromised keys and scam losses, said the month showed how quickly the threat picture can shift once attention moves elsewhere in the market.
The quarter’s biggest single loss came on September 25, when an attacker drained about $388 million from exchange Bitget’s hot wallet. The exchange paused withdrawals for all tokens, then walked them back in phases: bitcoin withdrawals resumed four days after the breach, ethereum followed on Tuesday and USDT on Wednesday, with everything else scheduled for October 2. Bitget has rebuilt its insurance fund to $309 million and says all remaining assets, fiat services and peer-to-peer trading will be back by October 2.
“Yes, it is bad optics. The reputational damage can still be larger than the losses themselves. Repeated exploits reinforce the idea that crypto infrastructure remains operationally fragile, which can slow institutional adoption, increase scrutiny from regulators and custodians, and make allocators demand a higher risk premium,” said Nicolai Sondergaard, senior research analyst at Nansen, in comments to CoinDesk.
On October 1, MetaMask pulled Ethereum staking validators offline after an infrastructure compromise diverted an estimated 0.36 ETH in block payments to another wallet. The company said no user funds were at risk, but the exits disrupted reward flows for stakers using Lido, which warned of lost rewards for affected validators. Small amounts, in this case, but the pattern is familiar: the compromise sat in operational infrastructure, not in the protocol itself, and the fix required shutting the whole staking product down first.
Insurance is shrinking, not growing
The safety net covering protocol users has been thinning. On-chain crypto insurance covered just $130.2 million at the end of August, down 20.2% from $163 million a year earlier, according to CoinGecko’s State of Crypto Security Report 2026. Value deposited on-chain has grown sharply over the same period, so coverage as a share of assets at risk has fallen further than the raw decline suggests. Exchange-level insurance funds, like Bitget’s rebuilt $309 million reserve, sit outside that on-chain number but serve a similar purpose for the biggest single venue loss of the quarter.
CoinDesk flagged the same imbalance early in the year: users chasing yields have largely skipped protection even when coverage exists. Most institutions never face the question. They buy through regulated ETF wrappers and stay away from DeFi protocols entirely, which is one reason the quarter’s losses have not dented the fund flows.
| Period | Incidents | Losses |
|---|---|---|
| September 2026 | 99 | $768.5 million |
| Q3 2026 | 247 | $1.26 billion |
| 2026 year to date | n/a | $2.68 billion |
AI tools are speeding up the attackers
Researchers expect artificial intelligence to make exploitation faster rather than fundamentally different. “My longer-term concern is speed, now AI tools are automating the hunt for weaknesses in smart contracts, work that used to take a skilled engineer months. That shortens the time anyone has to fix a flaw before it is used,” said Oliver Carding of Tesseract Group in an email quoted by CoinDesk.
Security vendor Blockaid has said it expects multiple incidents involving AI agents, with prompt injection, hidden instructions that push an agent into acting against its user, the most likely route in. That risk moved from theory to practice this quarter when OpenAI disclosed that unsecured agents had posted 53 user images publicly, an accidental exposure rather than an exploit, but an early example of agent infrastructure failing outside its intended boundaries.
The gap between attack speed and patch speed is the part nobody has solved. Automated audits now flag vulnerabilities the same way automated scanners flag them for attackers to look at, and the side that acts on the finding first is the side that gets the money. Teams running bug bounty programs have watched disclosure windows compress from weeks to days over the past year.
What the quarter shows about flow and optics
The two stories are not actually in conflict. ETF buyers get regulated, listed products with custodians of record, pricing and settlement on familiar rails. Hack losses concentrate in hot wallets, bridges and DeFi protocols, the parts of the stack that never reach the ETF balance sheet. Sondergaard’s point is that the reputational cost bleeds over anyway: every exchange withdrawal pause feeds the argument of allocators who already considered crypto operationally fragile, and regulators who already wanted narrower mandates for custodians.
Macro matters here too. BTC’s 40% quarter happened while the 10-year Treasury yield hit its highest level since 2002 and the 30-year pushed to levels last seen in July 2002, a backdrop that Citi cited when lifting its 12-month bitcoin target to $113,000 on October 1. The bank expects slow but steady ETF inflows of about $5 billion over the coming year as advisers raise allocations gradually, not a repeat of the third quarter’s rush.
For exchanges and protocol teams, the working assumption for Q4 is that attacker tooling keeps improving and that every hot wallet, bridge and admin key is a live target until proven otherwise. Bitget’s phased restart and MetaMask’s staking exit in the same 48 hours are the visible costs of that assumption. The ETF money keeps arriving regardless. The part that has to hold is everything around it.
