Crypto firms and users have absorbed nearly $2.7 billion in losses from security breaches so far in 2026, with attacks tied to North Korean actors exceeding $1 billion, according to new data from blockchain security firm CertiK.
Between January and September, CertiK logged 658 separate security incidents, resulting in approximately $2.26 billion in adjusted losses after around $420.4 million worth of stolen assets were frozen or recovered. On average, each incident led to a loss of $4.1 million.
September marked a dramatic escalation, with total losses reaching $766.5 million—surpassing April’s $651.3 million and becoming the costliest month of the year. Two major breaches dominated the landscape: Bitget’s $387.5 million exploit and the $318.7 million Liquid Network incident together accounted for over $700 million in damages.
This sharp increase has significantly skewed the annual loss distribution, concentrating a disproportionate share of losses among a handful of large-scale incidents rather than spreading them across numerous smaller ones. These trends have further elevated concerns around state-sponsored cyber activity, especially following blockchain analytics firm Elliptic’s finding that suspected North Korean hackers have stolen more than $1 billion this year.
Mega-breaches Dominate Annual Loss Profile
The surge in high-value hacks has reshaped the structure of 2026’s crypto-related financial losses, with a small number of massive breaches overshadowing hundreds of minor incidents.
Bitget and Liquid Network now top CertiK’s list of the year’s most damaging events. Bitget’s breach alone accounts for about 14.4% of all losses tracked by CertiK. Other notable incidents include KelpDAO ($291.3 million), Drift Protocol ($285.3 million), and an unnamed victim ($284.8 million). Collectively, these five incidents represent nearly $1.57 billion—roughly 59% of the total $2.68 billion lost in reported cases.

The increasing dominance of mega-hacks underscores how a single compromise—whether at a major exchange, protocol, or infrastructure provider—can dramatically shift the industry’s overall financial exposure. The combined impact of Bitget and Liquid Network equates to over $706 million, representing more than a quarter of CertiK’s total recorded losses for 2026.
Even within September alone, the disparity was stark; aside from those two major incidents, the rest of the month’s breaches contributed minimally to its overall loss figure.
In response, recovery efforts have gained momentum. CertiK reports that $420.4 million in assets have been successfully returned or frozen, lowering the net loss estimate to $2.26 billion. Notably, Liquid Network managed to recover a substantial portion of its stolen funds, reflecting growing collaboration between exchanges, issuers, and blockchain monitoring firms.
Despite these recoveries, the operational toll remains significant. Victims must often suspend services, restore user balances, reconstruct infrastructure, and allocate emergency capital even before any recovery occurs.
North Korea’s Crypto Operations Surpass $1 Billion Mark
As the frequency and severity of large-scale breaches rise, they amplify threats posed by persistent adversaries such as North Korea, whose cyber operations continue to drain global crypto ecosystems.
According to Elliptic, the Bitget breach pushed North Korea-linked thefts beyond $1 billion in 2026, involving more than 51 suspected incidents. Analysts assess the Bitget attack as highly indicative of North Korean involvement based on fund laundering patterns, reused infrastructure, and behavioral similarities with prior exploits.
Compared to CertiK’s $2.68 billion gross-loss estimate, Elliptic’s attribution of over $1 billion in North Korean activity represents over 37% of all documented crypto losses this year.
Previously, Elliptic had also connected the $286 million Drift Protocol exploit to North Korean actors, placing that organization behind yet another top-tier 2026 incident.
This pattern continues a long-standing trend: over the past decade, North Korean-backed groups have siphoned off billions, partly fueling the regime’s weapons development programs through illicit digital asset acquisitions.
Historically focused on traditional banking targets, these actors have shifted toward crypto businesses due to their decentralized nature, rapid liquidity, and borderless movement capabilities.
U.S. authorities have long identified the Lazarus Group—a unit under North Korea’s Reconnaissance General Bureau—as responsible for several high-profile crypto heists, including the infamous $620 million Ronin Bridge theft in 2022 and the $100 million Atomic Wallet breach.
Last year, Elliptic estimated cumulative losses linked to North Korea dating back to 2017 at over $6 billion—a figure bolstered by incidents like the record-breaking $1.46 billion theft from Bybit in February 2025, formally attributed to North Korea by the FBI.
Faced with enhanced tracking and freezing mechanisms, North Korean operatives are adapting rapidly. Elliptic notes increasing reliance on cross-chain transfers, mixing protocols, and obscure network channels to obscure transaction histories and evade detection systems.
With both volume and sophistication rising, North Korea stands out as one of the defining risks shaping the security landscape of the crypto economy in 2026.

