Bitget says attackers behind the theft of $387.5 million in cryptocurrency exploited a zero-day vulnerability in third-party security products, according to findings from blockchain security firm SlowMist.

The cryptocurrency exchange confirmed the development on Wednesday, saying investigators found malicious activity involving third-party security products and recovered a customized tool used to carry out unauthorized withdrawals.

Bitget first disclosed the attack on September 24, 2026, after threat actors transferred approximately $387.5 million from its hot and warm wallets. The exchange temporarily suspended withdrawals while investigating the incident. Around $632,700 worth of stolen cryptocurrency has since been frozen by Circle, Tether, and NEAR Intents.

According to Bitget’s investigation, the attackers exploited the vulnerability to obtain high-level internal credentials. Those credentials were then used to issue fraudulent withdrawal commands to the wallet system and initiate abnormal transfers that bypassed existing security controls. Bitget has notified the affected third-party vendor and disabled the compromised functionality while a fix is being completed.

The attack affected 11 blockchains, including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. The affected assets included XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, and TIA.

SlowMist’s latest progress report indicates that the earliest malicious activity connected to the attack dates back to August 31, 2026. Investigators found that a service running on one of the affected security product nodes had been compromised through a zero-day vulnerability. The attacker reportedly executed a hidden script through the service, retrieved a database password stored in an environment variable, and used it to connect to the database.

READ
Bitget Hack: Hackers Steal $351.6 Million in Crypto

Similar hidden-script activity was later identified on two other nodes on September 23 and September 25, suggesting that the affected service environments had already been compromised before the cryptocurrency transfers took place.

On September 25, the attacker also gained access to another security product’s management platform using the identity of an internal employee. Investigators found three attempts to inject system commands through task parameters to create malicious files.

The attacker subsequently used the platform’s web execution functionality to modify server configurations, create a communication relay file, and upload and assemble malicious programs in batches.

SlowMist also recovered a deleted, customized tool that was specifically designed around Bitget’s wallet withdrawal system. Investigators said the tool began executing the cryptocurrency theft at approximately 1:49 a.m. on September 25.

Mandiant’s investigation found that the attackers had gained unauthorized access to certain third-party security appliances and then used them to move laterally into Bitget’s wallet infrastructure. The attackers reportedly deployed a web shell on one of the security appliances, established a command-and-control connection, and used the persistent access to reach Bitget’s production wallet job server.

From there, malicious packages were deployed to the wallet environment, allowing the attackers to gain control of systems involved in processing cryptocurrency transactions.


Buy ExpressVPN with PayPal or Credit Card

Bitget said its IP activity analysis and blockchain investigation indicate that North Korean threat actors were behind the attack. Elliptic and TRM Labs also identified wallet overlaps connected to addresses used to launder cryptocurrency stolen in earlier attacks.

READ
Meta Denies Muse AI Agent Read Private Messages Without Permission
Advertisement