Publicly reported cryptocurrency exploits recorded between September 1 and September 7, 2026, totaled roughly $322 million, based on a consolidated review of project statements, on-chain investigators, and security-firm alerts issued at the time of each incident. The week was dominated by a single event on the Bitcoin sidechain Liquid Network, which alone accounts for more than 99% of the reported figure.
The remainder is spread across four confirmed on-chain drains on Ethereum, BNB Chain, and the XRP Ledger (XRPL). The totals below reflect figures reported at the time of each incident and do not include derivatives liquidations, malware that only uses public blockchains for command-and-control data, or exploits that began earlier and only received follow-up updates during the week.
Liquid Network Peg-Out: About 3,996 BTC Leaves the Federation Wallet
The largest event of the week, and the single largest publicly reported cryptocurrency incident of 2026 so far, was recorded on Blockstream’s Bitcoin sidechain Liquid Network on September 6.
According to a statement from Liquid-based decentralized exchange SideSwap, a customer sent 4,000 Liquid Bitcoin (L-BTC) to the SideSwap peg-out service at 14:05 Coordinated Universal Time (UTC). The L-BTC was burned under a valid peg-out authorization, and at 14:28 UTC the Liquid Federation paid approximately 3,996 BTC on the Bitcoin main chain. At about $80,000 per bitcoin as of 6:05 UTC on September 7, the withdrawal was valued at roughly $320 million.
In an on-chain incident notice posted at 8:25 PM UTC on September 6, Liquid Network said the withdrawal was routed through SideSwap’s Peg-out Authorization Key (PAK) and that the key itself had not been compromised, nor had any other federation keys. Public bridge nodes were disabled, and the sidechain was paused.
The federation added that other Liquid-issued assets, including Tether (USDT), DePix, and tokenized real-world assets (RWAs), were unaffected. The federation wallet’s remaining reserve stood at approximately 197 BTC, down from about 4,200 BTC before the peg-out.
An OP_RETURN (Operation Return) message attached to a follow-up Bitcoin transaction read: “we are whitehats. contact us on chain.” Blockstream, which develops Liquid’s infrastructure, replied on-chain and asked the party to contact security@blockstream.com.
Later on-chain messages indicated that most of the coins would be returned after every node was patched. Ledger Chief Technology Officer (CTO) Charles Guillemet said the conventional white-hat practice is to disclose a flaw before moving a large reserve rather than after. As of 6:15 UTC on September 7, the coins had not left the receiving address.
Independent on-chain analysis pointed to a range-proof cache flaw in Elements, the open-source software that powers Liquid’s confidential-transaction system. Reporting citing on-chain researchers said a fix had been merged into the Elements repository but was not included in the tagged build running on the network at the time of the incident.
For the full disclosure timeline and network response, see The Crypto Times report on the Liquid Network pause after ~4,000 BTC left the federation wallet.
Notional Finance: About $1.73 Million Escrow Drain on Ethereum
On Ethereum, decentralized finance (DeFi) fixed-rate lending protocol Notional Finance suffered a drain of an escrow contract worth about $1.73 million.
According to on-chain records, the alleged attacker submitted a setup transaction at 11:58:47 PM UTC on September 3, followed by a drain transaction at 12:01:35 AM UTC on September 4 in Ethereum block 25,900,234. The escrow released 69,257.38 Dai (DAI) and 1,658,524.864122 USD Coin (USDC), for a combined value of approximately $1.73 million. The attacker converted the stablecoins into about 689.2 Ether (ETH) and deposited them into the privacy tool Tornado Cash beginning at 12:15:59 AM UTC.
Blockchain-security monitor Specter first flagged the movement of funds, and PeckShieldAlert relayed the finding, saying the escrow “may have been exploited.” Later technical analysis attributed the drain to an integer overflow in an unsafe signed-to-unsigned downcast used in Notional’s free-collateral valuation, which allowed a fabricated liability to be truncated to zero so the position registered as debt-free.
On September 7, security firm SlowMist reported that two addresses on BNB Chain had opened malicious fCash positions using the same code pattern. Those positions had not matured, and no second drain had executed at the time of writing.
Further details on the setup transaction, drain transaction, and attacker path are covered in The Crypto Times report on the Notional Finance escrow contract facing the reported $1.7 million exploit.
XRPH Wallet: 4,011 XRP Ledger Wallets Emptied in Three Hours
On the XRP Ledger, a sweep of XRPH Wallet, a mobile application published by the XRP Healthcare project, emptied 4,011 user wallets in about three hours starting at 22:07 UTC on September 3.
A ledger review published after the event put the haul at approximately 267,664 XRP alongside XRPH and XRPHAI tokens, with a combined value of about $452,000 at the time of reporting. Forensic analysis attributed the breach to a design flaw in the wallet’s staking feature, which transmitted users’ seed phrases to a remote XRP Healthcare server when staking was activated.
Funds were subsequently moved through the cross-chain layer NEAR Intents onto Ethereum, where about 445,198 DAI held by the attacker remained unmoved in the published review. XRP Healthcare told users to stop using the application until further notice. The core XRP Ledger protocol was not affected.
Dream Health Chain: About $72,000 on BNB Chain
On September 5, on-chain trackers Monitoring Room and Web3 Daily Exploits documented an award-contract flaw in Dream Health Chain on BNB Chain that allowed a claimant to reset a claimed award and claim it repeatedly.
Trackers put the loss between $71,800 and $72,000 in USDT-equivalent value. Initial feeds noted that the funds remained in the attacker’s wallet at the time of writing.
Reddio RedSonic Vault: About 9.25 ETH via a Flash-Loan Path
Also on September 5, on-chain security service ExVul documented a single-transaction flash-loan exploit against Reddio’s RedSonic Vault on Ethereum.
According to ExVul’s alert, the attacker borrowed approximately 1,139 Wrapped Ether (WETH) from the decentralized exchange Balancer, registered a second share class through a permissionless path, inflated the share price by double-counting the borrowed collateral, redeemed both classes, swapped the proceeds on the decentralized exchange Curve, and repaid the loan in the same transaction.
The net profit was about 9.25 ETH, which Monitoring Room valued at roughly $23,000. The affected vault address is 0x4315…1126f, and the exploit transaction is 0xe3c..791a.
Events in the Same Week Excluded from the $322 Million Total
Several disclosures dated within the September 1 to September 7 window are logged separately to prevent double counting and to keep the headline figure comparable across weeks.
Ontology: The Ontology Foundation confirmed “malicious attack activity” on September 1 and resumed the chain on September 2 after deploying v3.1.5. Its statements said Ontology (ONT), Ontology Gas (ONG), and user assets were not compromised. Public trackers logged the incident at $0.
Injective: An application-level binary-options exploit on August 31 prompted an accelerated network upgrade. On September 1, the Injective Foundation said the chain, its consensus mechanism, and staked Injective (INJ) had not been compromised.
A second patch was executed at 17:43:41 UTC on September 2. A third-party estimate placed the application-level losses at about $4.8 million, though the project has not confirmed a figure. Additional context is available in The Crypto Times report on Injective confirming a secure network upgrade after the app exploit.
Core Decentralized Autonomous Organization (Core DAO): A reward-accounting flaw released approximately 255 million Core tokens (CORE) ahead of schedule between August 28 and August 31. The CoreRewardFix upgrade activated at 13:00 UTC on September 3 and removed 186.153 million CORE, with about 69 million CORE having already moved to external wallets. Core’s fixed 2.1 billion CORE maximum supply was not raised. The project’s disclosure came on September 5.
Coldcard Wave 3 movement: Digital-asset research firm Galaxy Research said at 02:19 UTC on September 7 that the Wave 3 operator had moved 97.09 BTC from 12 vaults, or about 45% of Wave 3 coins, through decentralized cross-chain swap protocol THORChain and Bitcoin CoinJoin transactions. Rank 1 moved 20.50 BTC on September 2 at 20:00 UTC, Rank 2 moved 15.48 BTC on September 5 at 14:41 UTC, and Ranks 3 to 11 moved on September 6.
The underlying seed-generation firmware bug dates back to July, and about 116.98 BTC across 282 vaults remained unspent.
Term Finance: Term Labs published its technical account of the August 23 governance drain on September 2 and said fixed-rate loan positions had been recovered by 14:52 UTC on August 25. Blockchain security firms PeckShield and CertiK had placed the original loss near $8.5 million.
ChatGPT-linked FXRP phishing: On September 3, blockchain investigator VAL published a $2.1 million trace of a phishing theft involving Flare’s bridged XRP token (FXRP). The theft is dated June 12 and does not fall within the September 1 to September 7 window.
ClickFix and EtherHiding: Reports dated September 1 and September 5 described malware that stores command-and-control addresses on Polygon or BNB Chain. These campaigns abuse public blockchains for data hosting rather than draining protocol treasuries and are not included in the total.
Week Total at a Glance
| Incident | Date (UTC) | Reported Amount | In $322M Total |
|---|---|---|---|
| Liquid Network | September 6, 14:05 to 14:28 | Approx. $320 million | Yes |
| Notional Finance | September 3, 23:58 to September 4, 00:01 | Approx. $1.73 million | Yes |
| XRPH Wallet | September 3, from 22:07 | Approx. $452,000 | Yes |
| Dream Health Vault | September 5 | Approx. $72,000 | Yes |
| RedSonic Vault | September 5 | Approx. $23,000 | Yes |
| Ontology | September 1 to 2 | $0 reported | No |
| Injective applications | Exploit 31; patches Sept 1 to 2 | Officially unpublished | No |
| Core DAO rewards | Exploit Aug 28 to 31; fix Sept 3 | Emissions pulled forward | No |
| BNB Chain Notional copy | September 7 alert | Not executed | No |
Outlook
The $322 million figure is highly sensitive to the outcome of the Liquid Network incident. If most of the withdrawn Bitcoin is returned once a patch is deployed, as the receiving party has indicated in on-chain messages, the net loss for the week will fall sharply. As of 6:15 UTC on September 7, no return had been recorded.
Public logs used for this inventory include Monitoring Room (updated September 6), YFarmX (updated September 6), Web3 Is Going Just Great, PeckShieldAlert, SlowMist, Galaxy Research, and XRPL.to. Those sources did not list any other valued protocol drain dated September 1, 2, or 7 beyond Liquid Network’s September 6 peg-out.
Also Read: Coldcard Hacker Moves 45% of Wave 3 Bitcoin via THORChain and CoinJoins
