A record month for crypto hacks sounds straightforward until some of the stolen money comes back.
That problem became particularly visible in September 2026. Two large incidents dominated the month: a breach at Bitget involving hundreds of millions of dollars and an exploit of Liquid Network that resulted in close to 4,000 BTC being withdrawn through its peg-out system. Yet the financial outcomes of the two incidents were substantially different.
The contrast highlights a limitation in one of the crypto industry’s most familiar security metrics. Reporting how much was initially lost or compromised is useful for measuring the scale of an attack, but it does not necessarily show how much value ultimately remained missing after recoveries, freezes, reimbursements and other post-incident actions.
For investors, users and security researchers, those are separate questions.
Gross Losses Measure the Attack, Not Always the Final Damage
When an attacker transfers $100 million from a protocol, recording a $100 million incident makes sense. That figure captures the amount compromised when the exploit occurred.
What happens afterward, however, can significantly change the economic outcome without reducing the severity of the original security failure.
Attackers sometimes return assets. Stablecoin issuers can freeze certain tokens. Exchanges may reimburse customers from corporate reserves or protection funds. Law enforcement agencies and security firms can also recover stolen assets later.
September provides a particularly clear example.
According to Liquid Network’s account of the incident, an attacker exploited a vulnerability in the Elements rangeproof verification cache on Sept. 6, creating approximately 4,000 L-BTC without corresponding Bitcoin backing. The attacker then used Liquid’s peg-out system to withdraw close to 4,000 BTC.
The initial exposure was enormous. But the financial picture changed quickly. According to Liquid, the attacker returned 3,400 BTC on Sept. 7 after communicating with the project’s team. Liquid’s subsequent incident assessment said approximately 602 BTC attributable to the unauthorized transactions remained subject to recovery efforts.
A monthly statistic based on the original amount affected therefore answers a different question from one based on the amount that ultimately remained unrecovered.
The distinction becomes particularly important when a small number of large incidents dominate aggregate figures. A recent analysis published by ChainReport shows how differently individual breaches can evolve after the initial loss, as recoveries, service restrictions and wallet-level responses alter the financial picture.
Recovery Rates Add Information That Hack Totals Cannot
That does not mean gross-loss statistics should be abandoned. Removing recovered funds from the original incident size would understate the scale of the security failure itself.
A vulnerability capable of exposing $300 million remains a serious vulnerability even if an attacker later returns most of the assets.
A more informative approach is to preserve multiple measurements rather than force every incident into a single loss figure.
Gross value affected can indicate the scale of successful attacks. Net unrecovered losses can show how much value remains missing after recoveries. Returned or frozen assets provide another measure of how much of the original exposure was subsequently contained.
Those figures can diverge sharply.
Historical cases illustrate why. Reuters reported that most of the roughly $610 million taken in the 2021 Poly Network attack was eventually returned. The exploit nevertheless remains a useful example of why the amount initially compromised and the amount permanently lost should not be treated as interchangeable figures.
Separating initial exposure from unrecovered losses preserves both pieces of information without minimizing the seriousness of the underlying breach.
Reimbursement Creates Another Accounting Problem
Bitget introduces a different complication.
The exchange initially estimated that approximately $351.6 million had been affected in its September incident. It later increased that figure to $387.5 million after accounting for additional transfers involving assets on Zcash and TRON.
According to Bitget’s account of the incident, a third-party security product was compromised, allowing the attacker to obtain internal access credentials and issue fraudulent withdrawal commands.
Unlike Liquid, the main accounting question is not primarily how much stolen cryptocurrency was returned. It is who ultimately absorbed the financial loss.
Bitget has said customer account balances remained unaffected because its Protection Fund absorbed the financial impact. The exchange subsequently reported that it had replenished the fund to more than $300 million after drawing on it in connection with the incident.
That creates two valid but distinct ways of describing the event.
From a cybersecurity perspective, approximately $387.5 million was transferred to attacker-controlled addresses, according to Bitget’s revised estimate. From the customer’s perspective, the exchange’s decision to absorb the damage meant account balances were not directly reduced by the theft, according to the company.
Neither perspective makes the other irrelevant.
This is why a single industry-wide “money lost to hacks” figure can struggle to describe fundamentally different outcomes. An unreimbursed protocol exploit, an exchange theft absorbed by a protection fund and an attack followed by a substantial recovery may produce similar gross-loss statistics while leaving users and affected organizations in very different financial positions.
Security Reporting Is Becoming an Accounting Exercise
As the crypto market matures, measuring hacks increasingly requires tracking what happens after an exploit rather than stopping when funds leave the victim’s control.
The industry already has mechanisms that make some of this possible. Public blockchains allow investigators to follow many stolen assets after an incident. Stablecoin issuers can sometimes identify and freeze tokens. Exchanges can disclose reimbursements, while projects can document returned funds and outstanding balances.
As a result, the significance of monthly loss totals can change over time.
A loss recorded on the day of an exploit may become partially recovered a week later. Another portion might be frozen months afterward. A platform could compensate customers even while the stolen assets remain under attacker control.
No single number captures all of those outcomes.
That makes both the timing and definition of loss figures increasingly important. A headline number recorded immediately after an exploit may accurately describe the scale of the breach while becoming a poor measure of its eventual financial impact.
Security reporting therefore benefits from treating hack losses as a moving picture rather than a fixed total. September’s figures still tell an important story about the scale of crypto’s security problem. But gross losses, unrecovered assets and user reimbursements measure different consequences of the same incidents.
Reporting them separately gives readers a clearer picture of both the security failure and its eventual financial cost.
