Daily Beirut

Tech & Science

PeckShield: Crypto Hacks Cost $766M in September

Crypto security firm PeckShield reports 55 major hacks in September caused $766.49 million in losses, driven primarily by incidents at Bitget and Liquid Network.

··3 min read
PeckShield: Crypto Hacks Cost $766M in September
Share

Security analytics firm PeckShield documented 55 significant cryptocurrency breaches during September, resulting in total losses of $766.49 million. This figure represents a roughly 462 percent increase compared to the $136.3 million lost in August, with just two incidents accounting for the vast majority of the damage.

The Largest Breaches of the Year

PeckShield identified the attack on the Bitget platform, valued at approximately $387 million, and the theft from Liquid Network, which involved nearly $320 million, as the largest and second-largest crypto heists recorded this year. Of the funds stolen from Liquid Network, $285 million has been recovered.

These two events surpassed earlier breaches targeting Drift and KelpDAO/LayerZero. When excluding these specific incidents, the remaining 53 attacks generated only about $59 million in losses, less than half of August’s total, according to reporting by CryptoPotato.

Bitget Security Incident Details

Bitget stated that its security systems detected unauthorized transfers from portions of its hot wallets on September 24. Chief Executive Gracy Chen explained that an attacker compromised the backend infrastructure within the wallet system, falsifying transaction data to deceive the authorization process into releasing funds.

Chen ruled out a compromise of private keys, noting that cold wallets holding most of the platform's assets remained untouched. The company plans to cover the loss through its user protection fund, which holds more than $464 million. Writing on X, Chen affirmed, "We will not run away from this matter, and every dollar lost will be compensated."

Liquid Network Theft and Recovery

The Liquid Network incident occurred earlier, on September 6, when hackers allegedly described as ethical actors withdrew approximately 4,000 Bitcoin from the Liquid Federation wallet. The withdrawal utilized SideSwap’s asset withdrawal authorization key, though Liquid noted the key itself was not breached.

Messages sent via the network to Blockstream indicated the intruder promised to return the funds once the security vulnerability across all nodes was fixed. Charles Guillemet, technical director at Ledger, expressed skepticism regarding this claim, stating that legitimate security researchers typically do not drain bridge contents before requesting contact.

Money Laundering and Ongoing Investigations

SlowMist reported in a September 29 update that hackers linked to North Korea are laundering stolen Bitget funds by linking protocol orders and deposit addresses on Chainflip, then converting proceeds to Bitcoin using CoinJoin technology to obscure transfer paths. SlowMist founder noted that anti-money laundering verification mechanisms no longer keep pace with automated software speed.

Chainflip is currently attempting to block these flows, having rejected at least one deposit and returning funds rather than freezing them. Among the other eight incidents listed in PeckShield’s top ten, values ranged between $3.15 million and $7.81 million.

The largest of these additional cases involved a preemptive operation by an account named "yoink," where funds were restored. Additionally, LimitBreak’s Payment Processor V2 contract, central to a "moral" rescue operation on September 25, held $6.6 million, with $3.4 million recovered. During that event, security researcher Quit moved 23,155 non-fungible tokens (NFTs) worth nearly $6 million from vulnerable wallets, while a separate exploit path resulted in the unrecoverable loss of 660 WETH.

Add Daily Beirut to your Google News feed to get the latest first.
Share