Bitget attributes $387.5 million wallet theft to third-party zero-day

Cryptocurrency exchange Bitget has confirmed that the theft of $387.5 million from its hot and warm wallets involved a zero-day vulnerability in third-party security products. The unauthorized transfers were disclosed on September 24, 2026, after which Bitget temporarily halted withdrawals while the incident was investigated.
Bitget said SlowMist identified malicious activity involving third-party products and recovered a customised tool used to initiate unauthorized withdrawals. The exchange said the flaw gave attackers high-level internal credentials, allowing them to send fraudulent withdrawal commands to the wallet system and trigger abnormal transfers that bypassed existing risk controls.
Compromise predates the transfers
SlowMist's progress report places the earliest malicious activity linked to the incident on August 31, 2026. A service on one node of an unnamed Product A was affected by a zero-day vulnerability. The attacker ran a hidden script under the service process, read an environment variable containing a database password, and connected to the database.
Similar hidden-script activity appeared on two other nodes on September 23 and September 25. SlowMist said these observations indicate that the affected service environments had been compromised before the cryptocurrency assets were transferred out.
On September 25, the attacker also accessed the management platform of another product, referred to as Product B, using an internal employee identity. SlowMist said the intruder made three consecutive attempts to inject system commands through task parameters in order to write malicious files. The attacker then used the platform's web execution endpoint in attempts to alter server configuration, create a communications relay file, and upload and assemble malicious program files in batches.
Wallet workflow targeted after lateral movement
Among deleted files recovered during the investigation was a bespoke program tailored to the wallet system's withdrawal logic. SlowMist said it began operating at 01:49 a.m. on September 25 and executed the cryptocurrency theft.
Mandiant found that the attackers obtained unauthorized access to third-party security appliances identified as A and B, then moved laterally into Bitget's wallet environment. The investigation found a web shell deployed on appliance B and a command-and-control connection established from it. Persistent access to that appliance was then used to reach Bitget's production wallet job server and deploy malicious packages.
Bitget has notified the relevant third-party vendor and disabled the affected functionality while a fix is completed. The incident affected 11 blockchains, including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand and Celestia. Identified assets include XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO and TIA.
Containment and operational lesson
Circle, Tether and NEAR Intents have frozen nearly $632,700 in cryptocurrency assets. Bitget said IP behaviour patterns and on-chain analysis point to North Korean threat actors, while Elliptic and TRM Labs identified wallet overlaps associated with laundering proceeds from earlier hacks.
For businesses operating high-value transaction systems, the case makes the operational boundary clear: third-party security infrastructure can become a route to production assets. Separating administrative access, protecting service credentials, and watching for abnormal commands across connected systems remain practical controls while vendor remediation is under way.

