$387.5 million: that is the sum Bitget says was stolen after attackers exploited zero-day flaws in third‑party security products and moved into the exchange’s wallet environment.
How the attackers pierced third‑party security appliances
Two independent investigations — one by blockchain security firm SlowMist and another by Google Cloud’s cyber‑defense arm Mandiant — concluded the intrusion began with zero‑day exploits in third‑party security appliances. SlowMist reported that "a service running on one of Product A's nodes was affected by a zero‑day vulnerability," after which "the attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database."
Mandiant's forensic account added operational detail: "on September 24, 2026, a threat actor gained unauthorised privileged access to Bitget's third party security appliances A and B. The threat actor deployed a web shell onto the security appliance B and established a Command‑and‑Control (C2) connection. Using the persistent access on security appliance B, the threat actor moved laterally to Bitget's production wallet job server and deployed malicious packages."
Timeline and mechanics of the intrusion and theft
SlowMist and Mandiant found initial traces of malicious activity well before the transfers began. SlowMist said, "The earliest malicious activity identified in the available logs dates to August 31," and observed similar hidden‑script activity on two other nodes on September 23 and September 25. According to the reporting, attackers dropped web shells on one compromised appliance and malware on Bitget's production wallet job server, then used a custom withdrawal tool to carry out the theft "after midnight on September 25."
SlowMist also provided a narrow window for the funds movements: "The earliest crypto theft transfer occurred on September 02:31 (UTC+8) and the last took place at 05:23," noting the operation spanned nearly three hours and covered multiple blockchains. Bitget detected multiple unauthorized transfers from hot and warm wallets and suspended all withdrawals on Thursday after discovering the theft.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadWhich assets and chains were affected
Bitget CEO Gracy Chen said the incident "affected multiple assets, including ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens," and that the theft involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains. The cross‑chain scope underlines the attackers' use of tooling capable of interacting with several ledger types during the narrow theft window.
Attribution claims and precedent cited by Bitget
Chen attributed the attack to North Korean hackers, saying Bitget's assessment was based on "IP behavior patterns and on‑chain analysis." Chen added that the attackers "breached a critical backend system within Bitget's wallet infrastructure that was later used to spoof transaction data, triggering the exchange's authorization process to move funds out of compromised hot/warm wallets."
The report also notes a broader context offered by Bitget: "North Korean hackers have been behind many other major crypto heists, including the Bybit hack, in which they stole $1.5 billion from the crypto exchange's ETH cold wallet." Those past incidents were cited in the article as examples linked to the same attribution claim.
Bitget response: withdrawals, bounty program, and unanswered vendor details
Following discovery of the unauthorized transfers, Bitget suspended all withdrawals and opened a Recovery Bounty Program offering bounties of 5% to those who help recover or freeze funds stolen in the attack. When BleepingComputer sought additional details "earlier today" about the zero‑day flaw and the specific third‑party security products compromised, "a Bitget spokesperson was not immediately available" to comment.
What this means for technologists, policymakers, and users
- Technologists and security teams: forensic findings here emphasize zero‑day risk in security appliances and the danger of hidden scripts reading environment variables that contain credentials. The combination of web shells, C2, lateral movement to a wallet job server, and deployment of malicious packages are concrete behaviors security teams will watch for in their own environments.
- Policymakers and regulators: the episode centers on an exchange suspending withdrawals after a multimillion‑dollar theft and publicly offering a recovery bounty, both actions regulators and oversight bodies are likely to examine when assessing operational resilience and incident disclosures.
- End users and customers of exchanges: users holding assets named by Bitget — ETH, XRP, BNB, AVAX, USDT, USDC and others — face immediate operational impacts from suspended withdrawals and uncertain timelines for recovery or asset return.
Bitget's account, and the forensic summaries from SlowMist and Mandiant, converge on a single disruptive chain of events: zero‑day compromise of third‑party security appliances, web shells and C2 established on an appliance, lateral movement to wallet infrastructure, deployment of malicious packages and a custom withdrawal tool — culminating in $387.5 million moved across multiple blockchains in a roughly three‑hour window. The vendor identity behind "Product A" and the two security appliances, along with additional technical details of the zero‑day, remain unconfirmed in public comments; Bitget did not immediately provide those specifics when asked.
Source: BleepingComputer — Bitget hacked via zero‑day in third‑party security products




