Bitget Hack: $387.5 Million Crypto Theft Linked to Zero-Day in Third-Party Security Product
Cryptocurrency exchange Bitget says attackers stole $387.5 million after exploiting a zero-day vulnerability in a third-party security product used within the exchange’s infrastructure.
Two separate investigations by blockchain security firm SlowMist and Google Cloud’s cyber defense arm Mandiant found that the attackers compromised two third-party security appliances before accessing Bitget’s wallet environment.
Attackers compromised Bitget’s wallet infrastructure
After gaining access, the attackers deployed a web shell on one of the compromised appliances and installed malware on Bitget’s operational wallet job server. They also deployed a custom withdrawal tool that was later used to initiate the cryptocurrency theft after midnight on September 25.
According to SlowMist, the earliest malicious activity found in the available logs dates back to August 31.
“A service running on one of Product A’s nodes was affected by a zero-day vulnerability. The attacker connected to the database by running a hidden script in the service process and launching a command that read environment variables containing the database password,” SlowMist said.
Investigators observed similar hidden-script activity on two other nodes on September 23 and September 25.
Mandiant said forensic evidence showed that a threat actor gained unauthorized privileged access to Bitget’s third-party security appliances A and B on September 24, 2026.
The attacker deployed a web shell on appliance B, established a command-and-control connection, and used persistent access to move laterally to a server. The threat actor then deployed a malicious package that enabled the subsequent cryptocurrency theft.
$387.5 million stolen across multiple blockchains
SlowMist said the first confirmed cryptocurrency theft transfer occurred at 02:31 UTC+8 in September, while the final transfer took place at 05:23. The attack therefore lasted nearly three hours and involved multiple blockchain networks.
Bitget suspended withdrawals on Thursday after detecting multiple fraudulent transfers from its hot and warm cryptocurrency wallets. The stolen assets included ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens.
The transactions involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base networks.
Bitget CEO Gracie Chen condemned the attack and attributed it to North Korean hackers, citing IP behavior patterns and on-chain analysis.
According to Chen, the attackers compromised critical backend systems within Bitget’s wallet infrastructure and used them to spoof transaction data. This spoofing triggered the exchange’s approval process for transferring funds from compromised hot and warm wallets.
North Korean hackers have been linked to several other large-scale cryptocurrency heists, including the Bybit hack that resulted in the theft of $1.5 billion from the exchange’s Ethereum cold wallets.
Bitget offers reward for recovering stolen funds
Following the breach, Bitget launched a recovery reward program. The exchange will offer a 5% reward to anyone who helps recover or freeze funds stolen in the attack.
A Bitget spokesperson was not immediately available when BleepingComputer requested additional information about the zero-day vulnerability and the third-party security products compromised in the attack.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



