TL;DR: Crypto lost $742.0M across 33 incidents in September 2026, nearly three times August's $255.5M, as attackers shifted from bad inputs to the systems that approve transactions and governance decisions, according to Quantstamp. Approval paths, not just contracts and wallets, now define the real attack surface.
Editorial analysis by NHI Mgmt Group, based on content published by Quantstamp: “September 2026: The Approval Layer Was Exploited”.
By the numbers:
- Crypto lost $742.0M across 33 incidents in September 2026.
- Bitget's $387M hack and Liquid Network's $320M exploit account for about 95% of September's losses.
- The other 31 incidents added up to $35.0M.
Key questions
Q: What breaks when approval systems are compromised instead of the contract itself?
A: When approval systems are compromised, the attacker no longer needs to defeat the application logic.
Q: Why do signer and governance paths create such high impact when abused?
A: Signer and governance paths matter because they sit above the application and can authorise many downstream actions at once.
Q: What are the warning signs that approval-layer trust is failing?
A: Look for unusual transfer volumes, proof checks that rely on stale cache state, admin changes that arrive through indirect paths, and proposal activity that can reassign privileged control.
Practitioner guidance
- Map the approval surface Inventory every system that can bless a transaction, proof, contract migration, or admin change, including signers, governance modules, caches, and vendor-integrated controls.
- Separate signing authority from upstream tools Remove direct paths from third-party products and routine admin credentials into systems that authorise transfers or contract changes, and require explicit, narrow delegation.
- Revalidate trusted decisions at the point of approval Do not rely on cached verification or inherited trust when the action is economically destructive or governance-changing; force a fresh decision before execution.
Bottom line: September's losses show that attackers are targeting the layer that approves transactions and governance changes, not only the code that executes them.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Approval-layer compromise is now the decisive security problem in digital asset systems. The article shows that attackers no longer need to defeat the transaction itself when they can compromise the authority that certifies the transaction. That shifts the real security boundary to signers, governance modules, and verification caches, which are often treated as support systems rather than critical control planes. Practitioners should model approval logic as a privileged trust service, not an implementation detail.
A question worth separating out:
Q: How should security teams govern approval authority in digital asset systems?
A: Treat approval authority as privileged infrastructure. Separate who can request an action from who can bless it, minimise the number of components that can influence authorisation, and review any path that lets third parties, delegates, or governance votes override application-level controls.
👉 Read our full editorial: September 2026 shows approval-layer attacks can outrun controls