PeckShield reported 55 significant cryptocurrency hacks in September, resulting in total losses amounting to $766.49 million. That figure represents an increase of approximately 462% compared to August’s $136.3 million, with two incidents responsible for nearly the entirety of this rise. The Bitget incident, amounting to approximately $387 million, and the Liquid Network theft, totalling around $320 million-of which $285 million was subsequently returned-are currently recognised as the largest and second-largest cryptocurrency thefts of the year, according to PeckShield. They progressed beyond the Drift and KelpDAO/LayerZero exploits. However, removing them along with the other 53 hacks results in a cumulative total of approximately $59 million, which is less than half of August’s overall figure.
As reported earlier by source, Bitget announced that its security systems identified unauthorised transfers from segments of its hot wallets at 18:31 on September 24. CEO Gracy Chen elucidated that the assailant infiltrated a backend system within the wallet infrastructure, manipulated transaction data, and deceived the authorisation process into disbursing funds. The CEO dismissed the possibility of a private key compromise and emphasised that cold wallets, which contain the majority of the exchange’s assets, remained untouched. The exchange intends to utilise its User Protection Fund, which currently exceeds $464 million, to offset the loss. The Liquid Network experienced a loss on September 6, when alleged white-hat hackers extracted approximately 4,000 BTC from the Liquid Federation wallet. The withdrawal utilised the SideSwap peg-out authorisation key; however, Liquid clarified that the key itself remained uncompromised.
In on-chain communications directed at Blockstream, the hacker assured that the funds would be returned once all nodes had been updated. Ledger CTO Charles Guillemet expressed scepticism, noting that credible security researchers would not ordinarily deplete a bridge and subsequently request to be contacted on-chain. SlowMist reported in a September 29 update that hackers associated with North Korea are engaging in the laundering of stolen Bitget funds. They are doing this by pairing CoW Protocol orders with Chainflip deposit addresses, converting the proceeds into BTC, and subsequently employing CoinJoin to obscure the transaction movements. Cos, SlowMist’s founder, contended that anti-money laundering checks are lagging behind automated scripts.
Chainflip is attempting to halt the flows and has denied at least one deposit, opting to refund the funds rather than freezing them. The remaining eight entries in PeckShield’s top 10 ranged from $3.15 million to $7.81 million. The largest incident involved a front-run executed by the MEV bot “yoink,” which was subsequently returned. Payment Processor V2, the LimitBreak contract involved in a white-hat rescue on September 25, accounted for $6.6 million, with $3.4 million returned. In that operation, security researcher Quit transferred 23,155 NFTs valued at approximately $6 million from compromised wallets, while an alternative exploit avenue resulted in 660 WETH remaining unrecovered.