Bitget hacked via zero-day in third-party security products

Bitget Crypto Exchange Hit with Record-Breaking Heist Thanks to Zero-Day Flaw in Security Products

A devastating cyberattack has left cryptocurrency exchange Bitget reeling after thieves stole a staggering $387.5 million from its systems last week. The breach, which is believed to have been carried out by North Korean hackers, was made possible by exploiting a zero-day vulnerability in third-party security products.

According to investigations conducted by blockchain security firm SlowMist and Google Cloud’s cyber-defense arm Mandiant, the attackers accessed Bitget’s wallet environment after compromising two security appliances with zero-day exploits. The breach allowed them to deploy web shells on one of the hacked appliances and malware on the exchange’s production wallet job server, as well as a custom withdrawal tool used to launch the cryptocurrency theft.

The earliest signs of malicious activity date back to August 31, when a service running on one of the compromised nodes was affected by the zero-day vulnerability. The attackers then ran hidden scripts under the service process, allowing them to connect to the database and gain unauthorized access. Similar activity was observed on two other nodes on September 23 and 25.

Forensic findings indicate that on September 24, a threat actor gained privileged access to Bitget’s third-party security appliances A and B. The attacker then deployed a web shell onto appliance B and established a Command-and-Control (C2) connection. Using the persistent access on appliance B, the attacker moved laterally to Bitget’s production wallet job server and deployed malicious packages.

The attack spanned nearly three hours across multiple blockchains, with the earliest crypto theft transfer occurring on September 2:31 UTC+8 and the last taking place at 05:23. The affected assets included ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens, involving various chains such as Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.

Bitget CEO Gracy Chen has blamed the attack on North Korean hackers, citing IP behavior patterns and on-chain analysis as evidence. The exchange’s wallet infrastructure was breached, allowing attackers to spoof transaction data and trigger the authorization process to move funds out of compromised hot/warm wallets.

This is not an isolated incident – North Korean hackers have been behind many other major crypto heists, including the $1.5 billion Bybit hack. Since the breach, Bitget has launched a Recovery Bounty Program, offering bounties of 5% to those who help recover or freeze funds stolen in the attack.

The alarming rate at which these attacks are occurring highlights the need for cryptocurrency exchanges and financial institutions to prioritize security measures, including regular updates and patching of security products. As attackers continue to exploit zero-day vulnerabilities, it is crucial that organizations invest in robust security protocols and stay vigilant against emerging threats.

In light of this incident, we urge all users to exercise caution when dealing with third-party security products and services. Regularly review your security configurations and ensure you are running the latest versions of software to prevent similar attacks from occurring on your systems.


Source: Bleeping Computer — 2026-09-30