Bitget hacked via zero-day in third-party security products
Bitget lost $387.5M in a hack exploiting zero-day flaws in third-party security products.
Summary
Cryptocurrency exchange Bitget suffered a $387.5 million theft after attackers exploited zero-day vulnerabilities in third-party security products. Investigations by SlowMist and Mandiant revealed the attackers compromised two security appliances, deployed web shells and malware, and then accessed Bitget's wallet environment to steal funds. Bitget's CEO attributed the attack to North Korean hackers, citing IP behavior and on-chain analysis.
Full text
Bitget hacked via zero-day in third-party security products By Sergiu Gatlan September 30, 2026 07:11 AM 0 Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. According to Bitget, two separate investigations by blockchain security firm SlowMist and Google Cloud's cyber-defense arm Mandiant said the threat actors accessed Bitget's wallet environment after compromising two security appliances with zero-day exploits. After the breach, the attackers dropped web shells on one of the hacked appliances and malware on the crypto exchange's production wallet job server, as well as a custom withdrawal tool used to launch the cryptocurrency theft after midnight on September 25. "The earliest malicious activity identified in the available logs dates to August 31. A service running on one of Product A's nodes was affected by a zero-day vulnerability. The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database. Similar hidden-script activity was observed on two other nodes on September 23 and September 25," SlowMist said. "Forensic findings indicate that on September 24, 2026, a threat actor gained unauthorised privileged access to Bitget's third party security appliances A and B. The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection. Using the persistent access on security appliance B, the threat actor moved laterally to Bitget's production wallet job server and deployed malicious packages," Mandiant added. SlowMist added that the earliest crypto theft transfer occurred on September 02:31 (UTC+8) and the last took place at 05:23, with the attack spanning nearly 3 hours across multiple blockchains. Bitget suspended all withdrawals on Thursday after detecting multiple unauthorized transfers from its hot and warm crypto wallets and discovering that attackers had stolen $387.5 million from them. CEO Gracy Chen noted the incident affected multiple assets, including ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens, and involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains. Chen also blamed the attack on North Korean hackers, citing IP behavior patterns and on-chain analysis as evidence, and added that they breached a critical backend system within Bitget's wallet infrastructure that was later used to spoof transaction data, triggering the exchange's authorization process to move funds out of compromised hot/warm wallets. North Korean hackers have been behind many other major crypto heists, including the Bybit hack, in which they stole $1.5 billion from the crypto exchange's ETH cold wallet. Since the breach, Bitget has launched a Recovery Bounty Program that offers bounties of 5% to those who help recover or freeze funds stolen in the attack. A Bitget spokesperson was not immediately available when BleepingComputer contacted them earlier today for more information on the zero-day flaw and the third-party security products compromised in the attack. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Bitget resumes Bitcoin withdrawals after $387.5 million crypto heistHackers steal $351.6 million in Bitget crypto exchange hackCalifornia man admits to laundering crypto stolen in $230M heistNorth Korean WaterPlum hackers infected 30,000 devices worldwideFrench tax authority data breach affects 678,000 individuals
Indicators of Compromise
- malware — web shell
- malware — custom withdrawal tool