Bitget hacked via zero-day in third-party security products
Bitget confirms attackers stole $387.5 million using zero-days in two third-party security appliances, deploying web shells and a custom withdrawal tool against hot wallets.
Bitget says attackers stole $387.5 million after exploiting zero-day flaws in two third-party security appliances to reach its wallet environment, per separate investigations by SlowMist and Mandiant. The actor ran hidden scripts to read a database password from an environment variable, deployed a web shell on appliance B with C2, and moved laterally to the production wallet job server with malicious packages and a custom withdrawal tool. The theft spanned nearly three hours across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, with the earliest malicious activity dating to August 31. CEO Gracy Chen attributed the attack to North Korean hackers citing IP behavior and on-chain analysis, and Bitget launched a Recovery Bounty Program offering 5% bounties.
- Zero-days in two third-party security appliances enabled $387.5 million theft from hot and warm wallets
- Web shell on appliance B provided C2; lateral movement deployed malware on the wallet job server
- Custom withdrawal tool spoofed transaction data over ~3 hours across seven blockchains
- Earliest malicious activity dated to August 31, per SlowMist forensic logs
- CEO attributes attack to North Korean hackers; Bitget offers 5% recovery bounties
Full article517 words · extracted from bleepingcomputer.com · click to collapse

Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products.
According to Bitget, two separate investigations by blockchain security firm SlowMist and Google Cloud's cyber-defense arm Mandiant said the threat actors accessed Bitget's wallet environment after compromising two security appliances with zero-day exploits.
After the breach, the attackers dropped web shells on one of the hacked appliances and malware on the crypto exchange's production wallet job server, as well as a custom withdrawal tool used to launch the cryptocurrency theft after midnight on September 25.
"The earliest malicious activity identified in the available logs dates to August 31. A service running on one of Product A's nodes was affected by a zero-day vulnerability. The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database. Similar hidden-script activity was observed on two other nodes on September 23 and September 25," SlowMist said.
"Forensic findings indicate that on September 24, 2026, a threat actor gained unauthorised privileged access to Bitget's third party security appliances A and B. The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection. Using the persistent access on security appliance B, the threat actor moved laterally to Bitget's production wallet job server and deployed malicious packages," Mandiant added.
SlowMist added that the earliest crypto theft transfer occurred on September 02:31 (UTC+8) and the last took place at 05:23, with the attack spanning nearly 3 hours across multiple blockchains.
Bitget suspended all withdrawals on Thursday after detecting multiple unauthorized transfers from its hot and warm crypto wallets and discovering that attackers had stolen $387.5 million from them.
CEO Gracy Chen noted the incident affected multiple assets, including ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens, and involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains.
Chen also blamed the attack on North Korean hackers, citing IP behavior patterns and on-chain analysis as evidence, and added that they breached a critical backend system within Bitget's wallet infrastructure that was later used to spoof transaction data, triggering the exchange's authorization process to move funds out of compromised hot/warm wallets.
North Korean hackers have been behind many other major crypto heists, including the Bybit hack, in which they stole $1.5 billion from the crypto exchange's ETH cold wallet.
Since the breach, Bitget has launched a Recovery Bounty Program that offers bounties of 5% to those who help recover or freeze funds stolen in the attack.
A Bitget spokesperson was not immediately available when BleepingComputer contacted them earlier today for more information on the zero-day flaw and the third-party security products compromised in the attack.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.