NewsCryptoBitget Confirms Third-Party Zero-Day Behind $387.5 Million Crypto Theft

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Crypto Theft

Author: Blocktelegraph·

Key Takeaways

  • •Bitget disclosed the $387.5 million theft on September 24, 2026, and temporarily suspended all withdrawals after attackers exploited a zero-day vulnerability in a third-party security product access its hot and warm wallets.
  • •SlowMist traced the earliest malicious activity to August 31, 2026, and recovered a deleted, customized tool built for the wallet system's withdrawal logic that began executing theft at 01:49 a.m. on September 25, 2026.
  • •Mandiant found that attackers gained unauthorized access to third-party security appliances, deployed a web shell with a command-and-control connection, and used persistent access to reach the production wallet job server where malicious packages were deployed.
  • •The incident affected 11 blockchains and at least 13 assets, including XRP, ETH, USDT, and USDC, with roughly $1.1 million in funds frozen by Circle, Tether, and NEAR Intents.
  • •Bitget attributes the attack to North Korean threat actors based on IP behavior patterns and on-chain analysis, and has disabled the affected third-party functionality pending completion of the vendor's fix.
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Crypto Theft

Bitget has confirmed that a zero-day vulnerability — a flaw unknown to its vendor and therefore unpatched when exploited — in a third-party security product was involved in the theft of $387.5 million, citing findings from an ongoing investigation by blockchain security firm SlowMist into unauthorized wallet withdrawals.

The exchange disclosed the incident on September 24, 2026, and temporarily suspended all withdrawals. According to Bitget, attackers gained access to hot and warm wallets — the internet-connected and intermediate tiers of an exchange's custody setup — through a series of unauthorized transfers. Per The Hacker News report, close to $1.1 million in assets have since been frozen — a small fraction of the amount taken — with the freezes carried out by Circle, Tether, and NEAR Intents. Issuer freezes rely on token-level controls: Circle issues USDC and Tether issues USDT, both listed among the affected assets, and each issuer can blacklist addresses at the smart-contract level.

Attacker Access to Withdrawal Systems

Bitget said the attackers exploited the flaw to obtain high-level internal credentials, which they then used to issue fraudulent withdrawal commands to the wallet system. The exchange characterized the resulting movements as "abnormal transfers that bypassed existing risk controls."

Bitget said it has notified the relevant third-party vendor and disabled the affected functionality pending completion of a fix. The intrusion path underscores a supply-chain risk that sits inside the security stack itself: the compromised products were protective tools, meaning the attackers' entry point came through the exchange's own defenses.

The incident spanned 11 blockchains: Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. Affected assets identified so far include XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, and TIA.

Hidden Scripts and Malicious Files

SlowMist traced the earliest malicious activity linked to the hack to August 31, 2026. Its report describes a zero-day vulnerability affecting a service on one of Product A's nodes. According to SlowMist, an attacker ran a hidden script under the service process; a command then read the environment variable containing the database password, allowing the attacker to connect to the database.

Investigators found similar hidden-script activity on two other nodes on September 23 and September 25, and said the affected service environments were compromised before the assets were transferred out.

The report also documents access to Product B's management platform on September 25, 2026. Using an internal employee's identity, an attacker made three consecutive attempts to inject system commands into task parameters in an effort to write malicious files, SlowMist said. The attacker subsequently submitted code through the platform's web execution endpoint. SlowMist further described attempts to modify server configuration, write a communication relay file, and upload and assemble malicious program files in batches.

Customized Wallet Tool and Mandiant Findings

SlowMist recovered a deleted, customized tool tailored to the wallet system's withdrawal logic and said the tool began executing cryptocurrency theft at 01:49 a.m. on September 25, 2026. That investigator timeline is separate from Bitget's September 24, 2026 disclosure date, and the report does not explain the difference.

Mandiant found that attackers had gained unauthorized access to third-party security appliances A and B, and said that access was used to move laterally into Bitget's wallet environment. According to Mandiant, the attackers deployed a web shell — a script that gives attackers a remote foothold on a compromised server — on appliance B and established a command-and-control connection. Persistent access then enabled movement to the production wallet job server, where malicious packages were deployed.

Attribution

Bitget said IP behavior patterns and on-chain analysis indicate that North Korean threat actors carried out the attack. Elliptic and TRM Labs identified wallet overlaps with laundering from hacks. That attribution remains Bitget's stated assessment.

The exchange's affected third-party functionality remains disabled pending completion of the vendor's fix.