Bitget hacked via zero-day in third-party security products
Bitget confirms attackers stole $387.5 million using zero-days in two third-party security appliances, deploying web shells and a custom withdrawal tool against hot wallets.
Bitget says attackers stole $387.5 million after exploiting zero-day flaws in two third-party security appliances to reach its wallet environment, per separate investigations by SlowMist and Mandiant. The actor ran hidden scripts to read a database password from an environment variable, deployed a web shell on appliance B with C2, and moved laterally to the production wallet job server with malicious packages and a custom withdrawal tool. The theft spanned nearly three hours across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, with the earliest malicious activity dating to August 31. CEO Gracy Chen attributed the attack to North Korean hackers citing IP behavior and on-chain analysis, and Bitget launched a Recovery Bounty Program offering 5% bounties.