Bitget’s Multimillion-Dollar Heist Exposed a Deep-Seated Vulnerability in Crypto Security
A staggering $387.5 million has been stolen from cryptocurrency exchange Bitget in what appears to be one of the most significant hacks of 2026, with attackers exploiting a zero-day flaw in third-party security products to breach the exchange’s systems. The heist, which took place on September 25, has left Bitget scrambling to recover lost funds and raise awareness about the critical vulnerability that was exploited.
According to investigations conducted by blockchain security firm SlowMist and Google Cloud’s cyber-defense arm Mandiant, attackers accessed Bitget’s wallet environment after compromising two security appliances with zero-day exploits. This allowed them to drop web shells on one of the hacked appliances and malware on the crypto exchange’s production wallet job server, as well as a custom withdrawal tool used to launch the cryptocurrency theft.
The earliest malicious activity was identified in logs dating back to August 31, when a service running on one of the security appliance nodes was affected by a zero-day vulnerability. The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database. Similar hidden-script activity was observed on two other nodes on September 23 and September 25.
Forensic findings indicate that on September 24, a threat actor gained unauthorized privileged access to Bitget’s third-party security appliances A and B. The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection. Using the persistent access on security appliance B, the threat actor moved laterally to Bitget’s production wallet job server and deployed malicious packages.
The attack spanned multiple blockchains, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains, affecting multiple assets such as ETH, XRP, BNB, AVAX, USDT, and USDC. Bitget’s CEO Gracy Chen has blamed North Korean hackers for the attack, citing IP behavior patterns and on-chain analysis as evidence.
The incident highlights a critical vulnerability in crypto security that needs immediate attention from industry players. Zero-day flaws in third-party security products can have devastating consequences when exploited by sophisticated attackers. As seen in this case, even top-notch security measures can be breached with a single zero-day exploit.
In the wake of the attack, Bitget has suspended all withdrawals and launched a Recovery Bounty Program that offers bounties of 5% to those who help recover or freeze funds stolen in the attack. As the crypto community comes together to support Bitget, it’s essential for exchange operators and security professionals to take proactive measures to mitigate similar risks.
To protect yourself from such attacks, we recommend staying vigilant about zero-day vulnerabilities and third-party security products used in your infrastructure. Regularly update and patch your systems, implement robust access controls, and maintain open communication channels with your security teams. By doing so, you can prevent a potential catastrophe like Bitget’s heist from happening to your organization.
Source: Bleeping Computer — 2026-09-30