NEWS

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Bitget says attackers used a zero-day in third-party security tools to steal $387.5M from hot wallets, per SlowMist and Mandiant findings.

Dylan H.

News Desk

October 1, 2026
7 min read
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

North Korea-Linked Actors Exploited Unpatched Security Appliances to Drain Bitget's Hot Wallets

Cryptocurrency exchange Bitget has confirmed that the theft of $387.5 million from its hot and warm wallets was made possible by a zero-day vulnerability in third-party security products deployed inside its infrastructure. The confirmation, disclosed around September 30, 2026, follows parallel investigations by blockchain security firm SlowMist and Google Cloud's Mandiant, both of which traced the intrusion back to August 31, 2026 — nearly four weeks before attackers began draining wallets on September 24. Bitget CEO Gracy Chen has attributed the operation to North Korean state-sponsored hackers based on IP behavior patterns and on-chain analysis, a conclusion independently supported by wallet-overlap findings from blockchain analytics firms Elliptic and TRM Labs.

The stolen figure itself shifted during the investigation: Bitget's initial disclosure put losses at roughly $351.6 million, which the exchange later revised upward to $387.5 million "based on the latest onchain tracing and classification of transactions."


Incident Details

AttributeValue
VictimBitget (cryptocurrency exchange)
Confirmed loss$387.5 million (revised up from an initial $351.6 million estimate)
Earliest known compromiseAugust 31, 2026
Theft execution windowSeptember 25, 2026, 02:31–05:23 (UTC+8), approximately 2 hours 52 minutes
Root causeZero-day vulnerability in a third-party security product ("Product A")
Secondary access vectorStolen internal employee credentials used against a second product ("Product B")
Blockchains affected11 — Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, Celestia
Assets stolenXRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, TIA
InvestigatorsSlowMist, Mandiant (Google Cloud)
Suspected attributionNorth Korean state-sponsored threat actor
Private keys compromisedNo — cold wallets and private keys reportedly untouched

How the Attack Unfolded

Initial foothold via a zero-day in "Product A" (August 31)

SlowMist's progress report, delivered after Bitget invited the firm to investigate on September 25, traces the earliest malicious activity to a service running on a single node of an unnamed third-party security product the firm anonymized as "Product A." According to SlowMist, the attacker exploited a zero-day flaw in that service, then "ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database." Neither SlowMist nor Mandiant has publicly named the affected vendor; Bitget says it has notified the vendor directly and disabled the vulnerable functionality pending a fix.

Similar malicious activity recurred on two additional Product A nodes on September 23 and September 25, indicating the attacker maintained persistent, low-profile access for weeks before moving toward the theft itself.

Lateral movement and credential theft ("Product B")

On September 25, the attacker separately accessed the management platform of a second third-party security product, "Product B," using the identity of an internal Bitget employee. Investigators observed three consecutive command-injection attempts against task parameters, used to deploy malicious files onto the compromised platform. Mandiant's findings describe the attackers deploying web shells on the compromised appliances and establishing command-and-control channels before pushing malicious packages to Bitget's production wallet job server.

A custom tool built to abuse withdrawal logic

Rather than stealing private keys outright, the attackers built and deployed a custom withdrawal tool specifically engineered to exploit the logic of Bitget's wallet withdrawal system. Using high-level internal credentials harvested during the intrusion, the tool issued fraudulent withdrawal commands that Bitget's own systems accepted as legitimate, triggering "abnormal transfers that bypassed existing risk controls." The actual drain was fast and systematic: the first theft transfer was logged at 02:31 (UTC+8) on September 25, with the last occurring at 05:23 — a window of roughly three hours spanning the 11 affected blockchains. Investigators later also observed forged Bitcoin withdrawal attempts following the initial drain.


Impact Assessment

Impact AreaDescription
Direct financial loss$387.5 million across 13 token types on 11 blockchains
Customer confidenceApproximately $463 million in customer outflows followed public disclosure of the hack
Recovered/frozen fundsClose to $1.1 million frozen by Circle, Tether, and NEAR Intents shortly after the theft
Reserve coverageBitget says losses are covered by its User Protection Fund, which held more than $464 million at the time
Operational disruptionWithdrawals were temporarily suspended fleet-wide, then resumed after remediation
Supply chain exposureTwo distinct third-party security products were compromised, highlighting risk inherited from vendor appliances inside exchange infrastructure
ReputationalPublic disclosure of unnamed, unpatched vendor products in a major exchange breach raises scrutiny of third-party security tooling across the crypto industry

Recommendations

For cryptocurrency exchanges and custodians

  • Treat third-party security appliances (EDR, SIEM, network security management platforms) as part of the attack surface, not just the defense layer — apply the same patching cadence, network segmentation, and credential hygiene expected of production systems.
  • Avoid storing plaintext database credentials in environment variables accessible to the service process; use a secrets manager with short-lived, scoped credentials instead.
  • Add independent, out-of-band verification for high-value withdrawal transactions that cannot be satisfied purely by internal system approval, so a single compromised credential or tool cannot authorize fraudulent transfers.
  • Segment wallet job servers and withdrawal infrastructure from general-purpose security tooling networks to limit lateral movement opportunities.

For security teams

  • Monitor for anomalous process behavior on security appliances themselves, including hidden or unscheduled scripts spawned under legitimate service processes.
  • Audit employee identity use on third-party vendor management platforms for signs of credential replay or unusual geographic/IP access patterns.
  • Maintain detailed, timestamped logging on security product nodes — SlowMist's reconstruction of this incident relied heavily on log data stretching back nearly a month before the theft was discovered.
  • Build incident response playbooks that assume vendor-supplied security software can itself be the initial access vector.

For end users

  • Monitor exchange communications for withdrawal suspensions or Recovery Bounty Program updates, and avoid interacting with unsolicited "recovery" offers related to the incident, which are common follow-on scams after high-profile breaches.
  • Diversify custody across exchanges and consider self-custody for long-term holdings to limit exposure to any single platform's infrastructure risk.

Key Takeaways

  1. Bitget confirmed $387.5 million was stolen after attackers exploited a zero-day vulnerability in a third-party security product, not a flaw in Bitget's own code.
  2. The intrusion began nearly four weeks before the theft, with the earliest malicious activity logged on August 31, 2026.
  3. Attackers compromised two separate third-party security products ("Product A" and "Product B"), using a zero-day exploit on one and stolen employee credentials on the other.
  4. A custom withdrawal tool was used to issue fraudulent transfers that bypassed Bitget's risk controls — private keys and cold wallets were not compromised.
  5. SlowMist and Mandiant both link the attack to North Korean state-sponsored actors based on IP patterns, on-chain tracing, and wallet overlaps with prior incidents.
  6. Neither investigating firm nor Bitget has publicly named the affected vendor products, underscoring how vendor-supplied security tooling can itself become an unmonitored attack surface inside critical financial infrastructure.

Sources