Bitget Confirms Zero-Day Behind $387.5 Million Crypto Theft

Bitget Confirms Zero-Day Behind $387.5 Million Crypto Theft

Bitget Confirms Zero-Day Behind 7.5 Million Crypto Theft

Bitget confirmed that a third-party security product zero-day was involved in the theft of $387.5 million. The cryptocurrency exchange cited findings from SlowMist’s ongoing investigation into unauthorized wallet withdrawals.

The exchange disclosed the theft on September 24, 2026, and temporarily halted all withdrawals. It said attackers accessed hot and warm wallets through a series of unauthorized transfers.

According to The Hacker News report, close to $1.1 million in assets have been frozen. Circle, Tether, and NEAR Intents carried out those freezes.

Illustrative physical cryptocurrency tokens on a wooden table
Illustrative physical cryptocurrency tokens on a wooden table. Illustrative stock photo via Pexels.

Bitget Describes Access To Withdrawal Systems

Bitget said attackers exploited the flaw to obtain high-level internal credentials. They used those credentials to issue fraudulent withdrawal commands to the wallet system.

The exchange described the resulting movements as “abnormal transfers that bypassed existing risk controls.” It has notified the relevant third-party vendor and disabled the affected functionality pending completion of a fix.

The incident impacted 11 blockchains: Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. Identified affected assets include XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, and TIA.

Investigators Trace Hidden Scripts And Malicious Files

SlowMist placed the earliest malicious activity linked to the hack on August 31, 2026. Its report described a zero-day vulnerability affecting a service on one of Product A’s nodes.

An attacker ran a hidden script under the service process, according to SlowMist. A command read the environment variable containing the database password, and the attacker connected to the database.

SlowMist found similar hidden-script activity on two other nodes on September 23 and September 25. It said the affected service environments were compromised before the assets were transferred out.

The investigation also described access to Product B’s management platform on September 25, 2026. An attacker used an internal employee’s identity and made three consecutive attempts to inject system commands into task parameters.

Those attempts sought to write malicious files, SlowMist said. The attacker subsequently submitted code through the platform’s web execution endpoint.

SlowMist described attempts to modify server configuration and write a communication relay file. It also reported efforts to upload and assemble malicious program files in batches.

Bitget Wallet Tool Examined In Separate Timeline

SlowMist recovered a deleted, customized tool tailored to the wallet system’s withdrawal logic. It said the tool began executing cryptocurrency theft at 01:49 a.m on September 25, 2026.

That investigator timeline is separate from Bitget’s September 24, 2026 disclosure date. The report does not explain the difference between those dates.

Mandiant found unauthorized access to third-party security appliances A and B. Investigators said attackers used that access to move laterally into Bitget’s wallet environment.

According to Mandiant, attackers deployed a web shell on appliance B and established a Command-and-Control connection. Persistent access then enabled movement to the production wallet job server, where malicious packages were deployed.

BlockTelegraph’s broader security and wallet coverage includes Bitcoin security planning, Frame’s post-quantum testnet, and stablecoin wallet distribution.

Bitget said IP behavior patterns and on-chain analysis indicate North Korean threat actors carried out the attack. Elliptic and TRM Labs identified wallet overlaps with laundering from previous hacks.

That attribution remains Bitget’s stated assessment. The exchange’s affected third-party functionality remains disabled pending completion of the vendor’s fix.

Facebook
Pinterest
LinkedIn
WhatsApp
Related Articles

Michael Peres (Mikey Peres) is a tech investor, web3 enthusiast, serial-entrepreneur, software engineer, journalist, and author best known for founding various technology, media, and news startups. As a regular contributor to reputable news publications such as Entrepreneur and Times of Israel, Peres leverages his experience to help other entrepreneurs and investors along their path to success.