0x04dbf05104db…04dbf054

ConfirmedSecurity596 vB35 sat/vB3 min decode

Bitget Confirms Third-Party Zero-Day Behind $387.5M Exchange Hack

Bitget says attackers exploited a zero-day in third-party security products to steal $387.5 million, with SlowMist tracing intrusion activity back to August 31, 2026.

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft - The Hacker News
WitnessBitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft - The Hacker NewsAI-generated

Outputs

  1. Bitget lost $387.5 million in unauthorized transfers from its hot and warm wallets on September 24, 2026.

  2. The breach exploited a zero-day vulnerability in third-party security products, confirmed by Bitget and SlowMist.

  3. The intrusion began as early as August 31, 2026, roughly a month before funds were moved.

  4. The theft spanned 11 blockchains including Ethereum, XRP Ledger, TRON and BNB Smart Chain.

  5. Circle, Tether and NEAR Intents have frozen close to $1.1 million in stolen assets; Bitget attributes the attack to North Korean threat actors.

Cryptocurrency exchange Bitget has confirmed that attackers who stole $387.5 million from its hot and warm wallets on September 24, 2026 exploited a zero-day vulnerability in third-party security products, citing ongoing investigation findings from blockchain security firm SlowMist.

In a statement on X, Bitget said the investigation "identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker to initiate unauthorized withdrawals."

The exchange disclosed the theft on September 24, 2026, reporting that threat actors drained funds through a series of unauthorized transfers, which forced a temporary halt on all withdrawals. Circle, Tether and NEAR Intents have since frozen close to $1.1 million in stolen cryptocurrency assets.

Bitget previously said the attackers used the flaw to obtain high-level internal credentials, then issued fraudulent withdrawal commands to the wallet system, triggering "abnormal transfers that bypassed existing risk controls." The exchange has notified the affected third-party vendor and disabled the compromised functionality pending a fix.

How did the attackers get in?

A progress report published by SlowMist traces the earliest malicious activity to August 31, 2026 — nearly a month before the funds moved.

"A service running on one of Product A's nodes was affected by a zero-day vulnerability," SlowMist said. "The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database."

SlowMist observed similar hidden-script activity on two other nodes on September 23 and September 25. "These findings show that the affected service environments had already been compromised before the assets were transferred out," the company said.

On September 25, the threat actor accessed the management platform of a second product, referred to as Product B, using an internal employee's identity. The attacker made three consecutive attempts to inject system commands into task parameters to write malicious files.

"The attacker subsequently submitted code through the platform's web execution endpoint, attempting to modify server configuration, write a communication relay file, and upload and assemble malicious program files in batches," SlowMist added.

Google-owned Mandiant, which is running a parallel investigation, found the attackers first gained unauthorized access to the two third-party security appliances and then moved laterally into Bitget's wallet environment.

"The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection," Mandiant said. "Using the persistent access on security appliance B, the threat actor moved laterally to Bitget's production wallet job server and deployed malicious packages."

What was stolen, and how?

The breach affected 11 blockchains: Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand and Celestia. Affected assets identified to date include XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO and TIA.

SlowMist also recovered a bespoke tool, among deleted files, tailored specifically to the wallet system's withdrawal logic. The program began executing the cryptocurrency theft at 01:49 a.m. on September 25, 2026, according to the report.

Bitget said IP behavior patterns and on-chain analysis point to North Korean threat actors. Blockchain analytics firms Elliptic and TRM Labs identified wallet overlaps with infrastructure previously used to launder proceeds from earlier hacks.

The confirmed supply-chain vector shifts scrutiny from Bitget's internal controls to the unnamed security vendors whose products were compromised, and the disclosure is likely to sharpen exchange-wide scrutiny of third-party appliance access to production wallet infrastructure as the investigation continues.

via twitter.com (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles