BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 30, 2026 · 2 min read · Original story

Bitget hacked via zero-day in third-party security products

Bitget hacked via zero-day in third-party security products

Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products.

According to Bitget, two separate investigations by blockchain security firm SlowMist and Google Cloud's cyber-defense arm Mandiant said the threat actors accessed Bitget's wallet environment after compromising two security appliances with zero-day exploits.

After the breach, the attackers dropped web shells on one of the hacked appliances and malware on the crypto exchange's production wallet job server, as well as a custom withdrawal tool used to launch the cryptocurrency theft after midnight on September 25.

"The earliest malicious activity identified in the available logs dates to August 31. A service running on one of Product A's nodes was affected by a zero-day vulnerability. The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database. Similar hidden-script activity was observed on two other nodes on September 23 and September 25," SlowMist said.

"Forensic findings indicate that on September 24, 2026, a threat actor gained unauthorised privileged access to Bitget's third party security appliances A and B. The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection. Using the persistent access on security appliance B, the threat actor moved laterally to Bitget's production wallet job server and deployed malicious packages," Mandiant added.

SlowMist added that the earliest crypto theft transfer occurred on September 02:31 (UTC+8) and the last took place at 05:23, with the attack spanning nearly 3 hours across multiple blockchains.

Bitget suspended all withdrawals on Thursday after detecting multiple unauthorized transfers from its hot and warm crypto wallets and discovering that attackers had stolen $387.5 million from them.

CEO Gracy Chen noted the incident affected multiple assets, including ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens, and involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains.

Chen also blamed the attack on North Korean hackers, citing IP behavior patterns and on-chain analysis as evidence, and added that they breached a critical backend system within Bitget's wallet infrastructure that was later used to spoof transaction data, triggering the exchange's authorization process to move funds out of compromised hot/warm wallets.

North Korean hackers have been behind many other major crypto heists, including the Bybit hack, in which they stole $1.5 billion from the crypto exchange's ETH cold wallet.

Since the breach, Bitget has launched a Recovery Bounty Program that offers bounties of 5% to those who help recover or freeze funds stolen in the attack.

A Bitget spokesperson was not immediately available when BleepingComputer contacted them earlier today for more information on the zero-day flaw and the third-party security products compromised in the attack.

References in this story

  1. Bitget (@bitget) on X x.com We are very grateful for SlowMist's quick response and professionalism in helping us investigate this incident thoroughly. They have shared their findings on the September 24 security incident. Their investigation…
  2. Hackers steal $351.6 million in Bitget crypto exchange hack www.bleepingcomputer.com ​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets.
  3. Gracy Chen @Bitget (@GracyBitget) on X x.com 刚才上午跟大家做了个三个多小时的直播,这里总结一下直播中聊到的点: ① Bitget 安全事件12小时进展通报。以下为具体信息,不打官腔。 ② 受影响资产包括ETH、XRP(单链损失最大)、BNB、AVAX、USDT、USDC及其他代币。涉及链包括:以太坊、XRP账本、Arbitrum、Avalanche、Optimism、BSC、Base。所有链上冷钱包已确认安全,未受波及。 ③…
  4. FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist www.bleepingcomputer.com FBI has confirmed that North Korean hackers stole $1.5 billion from cryptocurrency exchange Bybit on Friday in the largest crypto heist recorded until now.
  5. Hacker steals record $1.46 billion from Bybit ETH cold wallet www.bleepingcomputer.com Cryptocurrency exchange Bybit revealed today that an unknown attacker stole over $1.46 billion worth of cryptocurrency from one of its ETH cold wallets.
  6. Bitget Security Latest Incident Update: Fund Tracing and Recovery Bounty Program | Bitget Support Center www.bitget.com Latest StatusBitget's security team has identified the attack path and methods used in the incident, including details of how the attacker bypassed ex...

Guides related to this story

← Back to all news