Cryptocurrency suffered over $2.3 billion in losses across 86 major incidents by late September 2026, with Bitget's $351.6M hack being the latest. The attacks exploited vulnerabilities in supporting infrastructure—oracles, bridges, wallets, and governance systems—rather than blockchain technology itself, revealing that crypto security depends on securing systems and people surrounding smart contracts.
Crypto experienced over $2.3 billion in disclosed losses across 86 major incidents by late September 2026, with attacks ranging from wallet draining and phishing to oracle manipulation and social engineering. The sector's vulnerability extends beyond smart contract code to encompass trusted infrastructure components like oracles, bridges, and signing systems that attackers exploit to compromise blockchain security.
The $320M Liquid Network incident in 2026 resulted from a transaction-validation vulnerability allowing unbacked L-BTC creation, not from compromised private keys as commonly assumed. Blockstream recovered most funds and deployed patches, highlighting that bridge security requires proper validation logic alongside key management.
On September 6, 2026, an attacker exploited a vulnerability in Elements' rangeproof verification cache to create 4,000 unbacked LBTC on the Liquid sidechain, then withdrew approximately 4,000 BTC through the peg-out process. The attacker returned 3,400 BTC after negotiations, leaving about 602 BTC outstanding, while Blockstream deployed emergency patches to address the vulnerability.