Crypto firms and users have lost nearly $2.7 billion to security incidents this year, with North Korea-linked thefts exceeding $1 billion.
Blockchain security firm CertiK recorded 658 incidents through September, with about $420.4 million of stolen assets frozen or returned. That leaves adjusted losses of roughly $2.26 billion and an average loss of $4.1 million per incident.
September sharply altered the year's tally. Losses reached about $766.5 million, surpassing April's $651.3 million and making it the costliest month of 2026. Bitget's $387.5 million breach and the $318.7 million Liquid Network incident accounted for more than $700 million of the damage.
The surge has left the annual total increasingly dependent on a small number of outsized attacks. It has also brought state-linked theft deeper into the industry's security calculations after blockchain analytics firm Elliptic said suspected North Korean hackers have taken more than $1 billion in crypto this year.
Mega-hacks are reshaping the annual toll
September propelled Bitget and Liquid Network to the top of CertiK's 2026 incident ranking, widening the gap between the largest breaches and hundreds of smaller attacks.
Bitget alone represents about 14.4% of CertiK's year-to-date losses. Liquid Network ranks second, followed by KelpDAO at $291.3 million, Drift Protocol at $285.3 million, and an unidentified victim at $284.8 million.
Those five incidents account for about $1.57 billion, or almost 59% of the $2.68 billion recorded so far this year.
Bitget’s $387.5 million breach ranked as 2026’s largest reported crypto incident, ahead of Liquid Network and KelpDAO. Source: CertiKThat concentration means a single compromise at a large exchange, protocol, or infrastructure provider can materially change the industry's annual loss profile. For context, Bitget and Liquid Network together contributed roughly $706 million, equivalent to more than a quarter of all gross security losses tracked by CertiK in 2026.
September's figures further illustrate the imbalance. Beyond those two attacks, the month's remaining incidents contributed only a fraction of its $766.5 million total.
Meanwhile, some of the damage from these attacks has since been reversed. CertiK counts $420.4 million of assets as frozen or returned this year, reducing its adjusted loss figure to $2.26 billion. Liquid Network recovered a large portion of the assets involved in its incident, while other attacks have also resulted in partial or full returns.
So, the gap between gross and adjusted losses has widened as exchanges, issuers, security firms and blockchain operators move faster to identify and restrict stolen funds.
However, that recovery capacity does not eliminate the immediate cost to affected businesses. Large breaches can force operators to suspend services, replenish customer balances, rebuild infrastructure and commit capital before stolen assets are recovered.
Meanwhile, the attacks are also spreading across different parts of the crypto market. CertiK's annual data show incidents involving multiple blockchains have generated the greatest dollar losses, while Ethereum has recorded the largest number of security events.
The threat has extended beyond software. CertiK recorded 52 so-called wrench attacks during the first half of 2026, up from 39 in the same period last year. Exposure from those physical attacks climbed to $124.2 million from $10.5 million, while the average amount involved increased to about $2.4 million from roughly $270,000.
North Korea’s crypto theft machine crosses $1 billion in 2026
The growing size of individual breaches has amplified the impact of one of crypto’s most persistent adversaries.
Elliptic said the Bitget incident pushed the value stolen in attacks it attributes to North Korea above $1 billion in 2026, spanning more than 51 suspected incidents. The blockchain analytics firm assessed the Bitget breach as highly likely to be linked to the Democratic People’s Republic of Korea, citing laundering behavior, infrastructure shared with earlier attacks and other indicators.
Measured against CertiK’s $2.68 billion industrywide gross-loss figure, Elliptic’s North Korea tally equals more than 37% of security losses recorded this year.
Elliptic previously linked the roughly $286 million Drift Protocol exploit to North Korean actors. Drift is also among CertiK’s five largest incidents of 2026, putting suspected DPRK operations behind more than one of the year’s biggest crypto thefts.
The concentration extends a campaign that has generated billions of dollars for North Korea over the past decade.
Elliptic estimated last year that DPRK-linked hackers had stolen more than $6 billion in crypto since 2017, with governments and international organizations saying the proceeds help finance the country’s nuclear weapons and ballistic-missile programs.
North Korean hacking groups initially built a reputation by attacking banks and conventional financial infrastructure before increasingly targeting cryptocurrency businesses, where large pools of transferable assets can move across borders without relying on the traditional banking system.
The US Treasury designated Lazarus Group and related groups in 2019, describing them as state-sponsored operations controlled by North Korea’s Reconnaissance General Bureau.
Some of crypto’s largest historical breaches have since been attributed to the country. US authorities tied Lazarus to the roughly $620 million Ronin Bridge theft in 2022, while Treasury said the group used crypto mixers to launder proceeds from the $100 million Atomic Wallet attack and other hacks.
The escalation peaked in February 2025 when attackers stole about $1.46 billion from Bybit, the largest confirmed crypto theft on record. The FBI formally attributed that breach to North Korea, while Elliptic tracked the subsequent movement of funds through thousands of addresses, cross-chain services and laundering platforms.
Those laundering techniques have become more elaborate as exchanges, stablecoin issuers and blockchain analytics firms improve their ability to freeze and trace stolen assets. Elliptic said North Korean operators increasingly use repeated cross-chain transfers, mixers and less-monitored networks to break the transaction trail.
That leaves North Korea as one of the biggest variables in crypto’s 2026 security bill as the state-backed actors increasingly threaten the emerging industry.

By CryptoSlate | Created at 2026-10-02 06:47:45 | Updated at 2026-10-02 08:02:08
7 hours ago








