Attackers drained $387.5M through Bitget's own security appliances
Bitget confirms a third-party zero-day let attackers reach its wallet job server and drain $387.5M; SlowMist and Mandiant trace the two-stage path.
Bitget’s attackers walked in through the security products meant to keep them out. The exchange confirmed on Wednesday that the group that drained $387.5 million from its hot and warm wallets last week exploited a zero-day in third-party security appliances, then used that access to reach the server that issues withdrawals.
Two investigations back the account: SlowMist, a blockchain security firm, and Mandiant, Google’s incident response arm. They describe the same two-stage path through two separate third-party products, which both firms refer to only as A and B. Bitget has not named either vendor.
The earliest activity in the logs dates to August 31, nearly four weeks before any funds moved. SlowMist says a service running on one of Product A’s nodes was hit by a zero-day. The attacker ran a hidden script under that service’s process, read the environment variable holding the database password, and connected to the database directly. The same hidden-script pattern turned up on two more nodes on September 23 and 25, so multiple service environments were compromised before a single transfer went out.
On September 25 the attacker moved to Product B, reaching its management platform using an internal employee’s identity. SlowMist records three consecutive attempts to inject system commands into the product’s task parameters, then code submitted through the platform’s web execution endpoint to modify server configuration, write a communication relay file, and upload and assemble malicious program files in batches.
Mandiant’s account picks up the same thread from the network side. The attacker gained privileged access to appliances A and B on September 24, dropped a web shell on appliance B, and opened a command-and-control channel. From that persistent foothold on B they moved laterally to Bitget’s production wallet job server and deployed malicious packages. The security appliances became the distribution point for those malicious packages and the route to control over the wallet job server.
The withdrawal tool itself was bespoke. SlowMist recovered it from deleted files and describes it as tailored to the wallet system’s withdrawal logic. It began running at 01:49 on September 25. The first theft transfer followed at 02:31 (UTC+8), the last at 05:23, roughly three hours spread across multiple chains.
Bitget’s own summary is that the attackers used high-level internal credentials to issue fraudulent withdrawal commands and push through “abnormal transfers that bypassed existing risk controls.” CEO Gracy Chen described it as a compromise of a critical backend system that was then used to spoof transaction data, which tricked the exchange’s own authorization process into releasing funds. The authorization process was acting on data handed to it by a system the attacker already controlled.
The blast radius covers 11 blockchains: Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. Affected assets include XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, and TIA. Close to $1.1 million has been frozen so far by Circle, Tether, and NEAR Intents, a thin recovery against the total. Bitget has opened a bounty paying 5% to anyone who helps recover or freeze the stolen funds.
Attribution points to North Korea, based on IP behaviour and on-chain analysis. Elliptic and TRM Labs found overlaps between the laundering wallets and ones used in previous heists. North Korean hackers have been tied to other major crypto heists, including the Bybit hack, where $1.5 billion was taken from an ETH cold wallet.
A few things are worth pulling out for anyone running comparable infrastructure. A database password sitting in an environment variable was readable the moment a single service process was compromised, which is a common pattern and a common weakness. A security appliance with a web execution endpoint and a management platform that trusts an employee identity is a high-value target precisely because it already has privileged reach into the rest of the network. And a withdrawal pipeline that authorizes on transaction data, without an independent check on where that data came from, will sign whatever a compromised upstream hands it.
Bitget has notified the affected vendor and disabled the functionality involved while a fix is prepared. It has not said which products, and the spokesperson BleepingComputer contacted was not available to name the zero-day or the vendors.
Keep Reading
netscalerCitrix patches second NetScaler SAML bug in days
Citrix patched NetScaler zero-day CVE-2026-88779, a SAML memory overflow under active attack that causes denial-of-service and may allow code execution.
appleiOS CoreGraphics PoC published two days after the patch
Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics triggered by a malicious PDF font and used in targeted attacks on iOS before 27.
zammadTwo Zammad zero-days let an AI agent reach root
DIVD says two Zammad zero-days let an AI agent hijack a session, reach root, and exfiltrate data in seconds; network segmentation limited the breach.
Latest on the Wire
Full wire →- 16 Fake Firefox Extensions Stole Crypto Recovery PhrasesThe Hacker News
- AI Bolsters and Threatens Autocratic RegimesSchneier on Security
- AI Developer Launches Open-Source Adobe AlternativesArs Technica
- AI Helps Solve 15-Year Mystery of Obscure Band SalvageHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.