Security

Q3 2026's $1.26B in Crypto Hacks, By the Numbers

CertiK counted $1.26 billion lost to crypto hacks in Q3 2026, up 53.9% on Q2. Here is what the numbers show about custodial risk for miners.

Cover: NO HOT WALLET BETWEEN BLOCK AND YOU. A route of cards ends in one highlighted green exit, the miner's own address. Tess reads a receipt in the lower right.

Security firm CertiK closed the books on Q3 2026 with a number that stands out even in a year that had already produced several of them: $1.26 billion lost across 247 separate security incidents, a 53.9 percent jump from Q2's $819.4 million. Cointelegraph's rundown of the CertiK data landed the same day crypto press was also calling it a monster quarter for Bitcoin bulls, which is its own small irony: the asset had a good quarter, and so did the people stealing it. The Q3 2026 crypto hacks total is not one dramatic event. It is a quarter's worth of ordinary custodial failures, added up. Here is what the breakdown actually shows, and what it has to do with where a miner's own coins end up sitting.

Q3 2026's crypto hacks, in one table

Period Incidents Gross losses
Q2 2026 219 $819.4 million
Q3 2026 (full quarter) 247 $1.26 billion
September 2026 alone 99 roughly $769 million
2026 year-to-date n/a $2.68 billion

September did the most damage of any single month in 2026, and it did not happen quietly. Of that roughly $769 million, about $273 million was later frozen or returned, leaving adjusted losses of about $495 million. Two incidents carried most of that weight.

September's two biggest line items

The exchange Bitget disclosed a hot-wallet breach on September 24, and the loss has since been put at $387.5 million, about 31 percent of the quarter's total and the largest incident CertiK recorded. Bitget later said attackers used a zero-day flaw in third-party security products to obtain internal credentials and forge withdrawal commands. On September 6, the Liquid Network sidechain lost about $319 million in an exploit, ranking second for the quarter, though more than $270 million of September's losses was later returned. Different platforms, different code, same underlying shape: a wallet or a reserve that one operator controlled, and a single point where compromising the operator's own systems was enough to move what sat behind it.

What the two biggest losses have in common

Bitget's account holders did not lose money because they signed something they shouldn't have. The exchange lost it because its own infrastructure, the thing a customer has no way to inspect, was compromised. That is the defining shape of a custodial loss: the damage happens upstream of anything the account holder could have personally checked or prevented, in systems the account holder never gets to see, let alone audit. A Q3 total of $1.26 billion is what happens when that shape repeats itself 247 times in thirteen weeks across exchanges, protocols, and sidechains, many of which hold funds on behalf of someone else.

NexusPool's structural alternative: nothing to hold

A solo mining pool does not have to replicate that risk, and the difference is not a matter of better security practices, it is a matter of what the pool is holding in the first place. NexusPool's own version of that point is blunt: the block pays your address. There is no balance for us to hold. That is a direct consequence of a 0 percent pool fee and a coinbase transaction, the one line in a block that mints the new coins, written to pay the finder's own address, not a pool-operated wallet. NexusPool's Payout Preflight tool shows the exact coinbase before you find a block, letting a miner enter their own address and see what it would actually pay on the current block, built by the same code that builds a real one, so that payout structure is not something a reader has to take on faith either. Each hour, the pool also signs a receipt, its Glass Ledger, covering the shares it counted from each rig, the difficulty it served them at, and the window they landed in, checkable on NexusPool's Glass Ledger page or in a reader's own code against the key the pool publishes.

None of this means non-custodial mining removes risk entirely. A miner who loses their own private key, sends to the wrong address, or runs compromised firmware on their own machine can still lose funds, and no architecture fixes a mistake made on a miner's own device. NexusPool is free software with a 0 percent pool fee, not an investment product, and nothing here promises a particular return or a faster block. What changes with a non-custodial design is narrower and more specific: there is no exchange-style hot wallet sitting between a found block and the miner's own address, which is the kind of single point of failure behind the quarter's largest custodial loss. NexusPool's terms page spells out what the pool does and does not hold on a miner's behalf, in plain language rather than marketing language.

The numbers above are not a reason to panic about any specific exchange. They are a reason to ask a boring, specific question about any platform holding coins on your behalf: who actually controls the key, and what happens to your funds if that operator has a bad quarter. For a solo miner, that question has a simple answer to check, not just trust. Open Payout Preflight, enter the address you mine to, and confirm that the coinbase pays you, not a balance you would later need to withdraw.

Trust nothing. Verify where your mined coins actually sit.