# "smart contract" (exploit OR hacked OR drained) — X 热门讨论 (2026-09-25 09:04 UTC)
## @Elikrypt (ΞLIKRYPTO) · 09-25 05:02 · ♥81 ↻1 💬41 Crypto hacks in 2026 have now passed $2.3B
As of September 25, around $2.34B has been involved in 86 major crypto security incidents.
That’s the gross figure. Some of the money was recovered, frozen, or returned.
THE BIGGEST HITS
January — individual wallet theft, ~$282M Attackers posed as hardware-wallet support and convinced victims to give up their recovery phrases.
April 1 — @DriftProtocol, ~$285M Attackers gained control of critical security systems, manipulated collateral values, and drained the protocol.
April 18 — @KelpDAO, ~$292M Attackers compromised cross-chain infrastructure, forged messages, minted unbacked rsETH, and converted it into real assets.
July — @COLDCARDwallet, ~$114M A weakness in recovery-phrase generation allowed attackers to reconstruct private keys from affected wallets.
September 6 — @Liquid_BTC, ~$319M Attackers exploited Elements’ validation process to create unbacked L-BTC and convert it into BTC. About 85% was later returned, with roughly $47M remaining according to @trmlabs.
September 24 — @bitget, ~$351.6M affected Bitget detected unauthorized transfers from part of its hot and warm wallet infrastructure.
Bitget said cold wallets remained secure and its $464M+ protection fund covered the affected amount.
The exchange later said a compromised backend wallet-service system generated false transfer information that reached the signing process.
Bitget CEO Gracy Chen also said some IPs matched VPN infrastructure previously linked to a North Korean hacking group. Bitget suspects Lazarus, but the attribution has not been confirmed.
These six incidents account for roughly $1.64B. The other 80 make up the remaining ~$700M.
HOW THEY GOT IN
The weak point was not always the smart contract.
Private keys → governance → bridges → wallets → infrastructure → exchanges.
Attackers went after whatever had enough access to approve, validate, create, or sign transactions.
That includes:
→ Private keys → Multisig signers → Price feeds → Bridge verifiers → RPC systems → Wallet software → Backend services
A protocol can have audited contracts and still lose money because something around those contracts was compromised.
Bitget is a good example.
The transfers happened on-chain, but the reported problem was higher up the chain of operations, inside a backend system connected to the wallet-signing process.
HOW TO LIMIT THE DAMAGE
Keep less money in hot wallets.
Separate transaction creation from approval.
Require another check for large or unusual transfers.
Set limits on amounts, frequency, and destinations.
Pause activity that suddenly looks abnormal.
Avoid single points of failure in bridges and critical security systems.
Monitor the systems behind the wallets, not just the blockchain.
WHERE SECURITY NEEDS TO IMPROVE
The $2.34B figure needs context. Stolen, recovered, frozen, returned, and permanently lost funds are different numbers.
But 2026 has made one thing clear: securing the smart contract is not enough.
Keys, wallets, people, backends, bridges, and signing systems can all become the point of failure.
One compromised part should not be enough to move hundreds of millions.
Reduce access. Reduce exposure. Limit the damage. https://x.com/Elikrypt/status/2103349293604090250