Bitget Confirms $387.5 Million Heist Stemmed from Zero-Day Exploits in Third-Party Security Products
Cryptocurrency exchange **Bitget** has revealed that a sophisticated attack last week, resulting in the theft of $387.5 million, was initiated through the exploitation of zero-day vulnerabilities in two third-party security appliances. Investigations by **SlowMist** and **Mandiant** confirm that threat actors gained privileged access before deploying web shells, malware, and a custom withdrawal tool.

Cryptocurrency exchange **Bitget** today confirmed that the recent $387.5 million heist was the result of threat actors exploiting zero-day vulnerabilities within its third-party security products.
### Sophisticated Attack Chain Uncovered
Independent investigations conducted by blockchain security firm **SlowMist** and **Google Cloud**'s cyber-defense arm, **Mandiant**, have corroborated the findings. Both reports indicate that attackers compromised two security appliances using previously unknown zero-day exploits.
Following the initial breach, the threat actors deployed web shells on one of the compromised appliances and installed malware on **Bitget**'s production wallet job server. They also introduced a custom withdrawal tool, which was subsequently used to execute the cryptocurrency theft after midnight on September 25.
**SlowMist**'s report details the earliest malicious activity detected: "The earliest malicious activity identified in the available logs dates to August 31. A service running on one of Product A's nodes was affected by a zero-day vulnerability. The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database. Similar hidden-script activity was observed on two other nodes on September 23 and September 25."
**Mandiant**'s forensic findings further elaborate: "Forensic findings indicate that on September 24, 2026, a threat actor gained unauthorised privileged access to **Bitget**'s third party security appliances A and B. The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection. Using the persistent access on security appliance B, the threat actor moved laterally to **Bitget**'s production wallet job server and deployed malicious packages."
### The Theft and Its Aftermath
**SlowMist** noted that the actual crypto transfers began at 02:31 (UTC+8) on September 26 and concluded at 05:23, spanning almost three hours across multiple blockchains.
**Bitget** swiftly suspended all withdrawals upon detecting the unauthorized transfers from its hot and warm crypto wallets, confirming the theft of $387.5 million.
**Bitget** CEO **Gracy Chen** stated that the incident impacted a wide array of assets, including **ETH**, **XRP**, **BNB**, **AVAX**, **USDT**, **USDC**, and other tokens across the **Ethereum**, **XRP Ledger**, **Arbitrum**, **Avalanche**, **Optimism**, **BSC**, and **Base** chains.
### Suspected North Korean Involvement
Chen also pointed towards North Korean hackers as potential culprits, citing IP behavior patterns and on-chain analysis. She indicated that these actors breached a critical backend system within **Bitget**'s wallet infrastructure, which was then used to spoof transaction data and trigger the exchange's authorization process to move funds.
North Korean state-sponsored hacking groups have a history of targeting cryptocurrency exchanges, with notable incidents including the **Bybit** hack, where they reportedly stole $1.5 billion from the exchange's **ETH** cold wallet.
In response to the breach, **Bitget** has launched a Recovery Bounty Program, offering a 5% bounty to individuals who can assist in recovering or freezing the stolen funds.