Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
Bitget says attackers exploited a zero-day in an unnamed third-party security product to steal $388 million from hot and warm wallets.
Bitget disclosed that the attacker behind the $388 million theft exploited a zero-day flaw in a third-party security product to obtain high-level internal credentials. On September 24, the attacker injected fraudulent withdrawal commands into wallet backend services, starting with two small test transfers that evaded risk controls before larger transfers were executed. Cold wallets and private keys were unaffected, and Bitget's Protection Fund will cover the loss, with Bitcoin withdrawals reopening September 28. Bitget suspects the same North Korean group it previously blamed; TRM Labs found laundering overlaps with the TraderTraitor cluster, while Mandiant and SlowMist support the investigation.