Cryptocurrency exchange Bitget confirmed Wednesday that hackers who stole $387.5 million last week exploited a zero-day vulnerability in third-party security products to gain access to internal systems and drain its wallets. The confirmation came from an ongoing investigation led by blockchain security firm SlowMist, which recovered a custom-built tool the attackers used to execute unauthorized withdrawals. The breach, disclosed September 24, 2026, targeted the exchange's hot and warm wallets through a series of fraudulent transfers, forcing Bitget to temporarily suspend all withdrawals.
According to SlowMist's findings, the earliest malicious activity tied to the hack occurred on August 31, 2026—nearly a month before the theft itself. The attackers compromised 11 blockchains, including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. Stolen assets identified so far include XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, and TIA. Nearly $1.1 million in cryptocurrency has been frozen by Circle, Tether, and NEAR Intents. The bespoke theft tool recovered by investigators began running at 1:49 a.m. on September 25, 2026, and was specifically designed to match the wallet system's withdrawal processes.
SlowMist reported that a service running on one of the affected security products' nodes was hit by the zero-day vulnerability, allowing the attacker to execute a hidden script that read environment variables containing database passwords and connected to the database. "Similar hidden-script activity was observed on two other nodes on September 23 and September 25," the firm stated, adding that the compromised service environments had been breached before any assets moved out. On September 25, the threat actor accessed another security product's management platform using an internal employee's identity, making three consecutive attempts to inject system commands into task parameters to write malicious files. Bitget said the attackers leveraged the flaw to obtain high-level internal credentials, then used them to issue fraudulent withdrawal commands and initiate "abnormal transfers that bypassed existing risk controls."
Google-owned Mandiant's investigation found that the attackers gained unauthorized access to certain third-party security appliances, then moved laterally into Bitget's wallet environment by deploying a web shell onto one appliance and establishing a command-and-control connection. Using that persistent access, the threat actor moved laterally to Bitget's production wallet job server and deployed malicious packages. Bitget has notified the relevant third-party vendor and disabled the affected functionality while a fix is being developed. IP behavior patterns and on-chain analysis point to North Korean threat actors as the perpetrators, with blockchain intelligence firms Elliptic and TRM Labs identifying wallet overlaps used to launder proceeds from previous hacks. The breach highlights how security tools themselves can become attack vectors when zero-day vulnerabilities allow adversaries to turn protective infrastructure into entry points. For enterprises holding digital assets, the incident underscores that third-party risk management requires continuous monitoring even of systems designed to protect against intrusions.

