
Bitget $387.5M Theft Linked to Zero-Day in Security Appliances
Bitget confirms a zero-day in third-party security products enabled the theft of $387.5 million from its hot and warm wallets on September 24.
Bitget, the cryptocurrency exchange, said on Wednesday that the $387.5 million theft from its hot and warm wallets on September 24, 2026 was made possible by a zero-day vulnerability in third party security products. The exchange cited ongoing investigation findings from blockchain security firm SlowMist, which Bitget described in a post on X. A zero day vulnerability is a security flaw that the affected vendor did not know about and had not patched when attackers began using it.
The incident began with a series of unauthorized transfers that moved funds out of Bitget's hot and warm wallets, the internet connected and partly connected wallets an exchange uses to process fast withdrawals. Bitget temporarily stopped all withdrawals after noticing the activity. Circle, Tether, and NEAR Intents have frozen close to $1.1 million in cryptocurrency assets linked to the theft. The affected transfers touched 11 blockchains: Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. Assets identified so far include XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, and TIA. Bitget said the attackers used the flaw to obtain high level internal credentials, then issued fraudulent withdrawal commands to the wallet system and started abnormal transfers that bypassed existing risk controls. The exchange has notified the relevant third party vendor and disabled the affected functionality until a fix is complete.
SlowMist's progress report puts the earliest malicious activity at August 31, 2026. According to the firm, a service running on one of the nodes of a product it calls Product A was affected by the zero day vulnerability. The attacker ran a hidden script under the service process, launched a command to read an environment variable containing the database password, and connected to the database. Similar hidden script activity appeared on two other nodes on September 23 and September 25, showing that those service environments were already compromised before the assets were transferred out. On September 25, the attacker used an internal employee identity to access another product, named Product B, and made three consecutive attempts to inject system commands into the product's task parameters in order to write malicious files. SlowMist added that the attacker later submitted code through the platform's web execution endpoint, trying to modify server configuration, write a communication relay file, and upload and assemble malicious program files in batches. The company also recovered a bespoke tool from among deleted files. This program was highly tailored to the wallet system's withdrawal logic and began running and executing cryptocurrency theft at 01:49 a.m. on September 25, 2026.
Google owned Mandiant, which also investigated the incident, found that the attackers gained unauthorized access to certain third party security appliances, referred to as A and B, and then used that access to move laterally, meaning from one compromised device to another inside the same network, into Bitget's wallet environment. The threat actor deployed a web shell, a small hidden program that allows remote commands, onto security appliance B and established a Command-and-Control (C2) connection, the channel an attacker uses to remotely manage an infected system. Mandiant said the persistent access on security appliance B let the threat actor move laterally into Bitget's production wallet job server and deploy malicious packages. In its findings, Mandiant stated that the threat actor compromised network and security appliances and leveraged them to distribute malicious packages and gain control over the wallet job server.
Bitget said IP behavior patterns and on chain analysis, which means tracing transactions on public blockchain records, point to North Korean threat actors as responsible. Elliptic and TRM Labs, two blockchain analytics firms, uncovered wallet overlaps used to launder illicit proceeds obtained from previous hacks. For website owners and businesses, the case is a sharp reminder that a trusted third party device can become the pivot point into the most sensitive internal systems, and that those appliances must be kept patched, segmented, and monitored just like production servers. For organizations that depend on third party security products, this incident underlines why those devices should be inventoried and separated from wallet or payment systems; that kind of security first infrastructure review is part of what AEU-I, the security focused IT and consulting arm of AEU Group, offers its clients.
How to Protect Yourself
- If you hold cryptocurrency on an exchange, keep only the amount you need for active trading there and store the rest in a wallet you control offline.
- Make a list of every outside security tool your website or business uses, then check each maker's website for security updates and install them right away.
- Turn on two step login for every administrator account and for any system that can move money.
- Ask your IT provider to separate payment or wallet systems from other tools, so one hacked device cannot reach them.
- If any security vendor announces a problem, stop using that tool or feature until the maker releases and you install the fix.
Terms Explained
- zero-day vulnerability A security hole in software that the maker did not know about and had not fixed when attackers started using it.
- hot wallet A cryptocurrency wallet that is connected to the internet so an exchange can process quick withdrawals.
- warm wallet A cryptocurrency wallet that is only partly connected to the internet and used for medium speed transfers.
- web shell A small hidden program an attacker places on a server so they can send commands to it from anywhere.
- Command-and-Control (C2) The private channel an attacker uses to remotely control a compromised system.
- lateral movement The act of hopping from one hacked computer to another inside the same network to reach a more valuable target.
- on-chain analysis The practice of reading public blockchain records to trace where cryptocurrency has been moved.