Bitget revealed that the attackers who stole $387.5 million on September 25, 2026, managed to compromise its wallet environment by exploiting zero-day vulnerabilities in two third-party security devices. This was according to two separate investigations conducted by blockchain security firm SlowMist and Google Cloud’s cyber defense unit, Mandiant.
The findings show that the breach did not begin directly with Bitget’s wallets, but with external security devices identified in the two investigations as Product A and Product B. Logs recorded the earliest malicious activity on August 31, when the attackers exploited a service running on one of Product A’s nodes and executed an obfuscated script under the service account to read an environment variable containing the database password and connect to it.
From the Vulnerability to the Wallet Environment
According to Mandiant, the attackers obtained elevated and unauthorized privileges on the two security devices on September 24. They then planted a web shell on Device B and established a connection with a command-and-control server. Through this access, they moved laterally to Bitget’s production wallet task server, where they deployed malicious packages.
The investigations also detected malware on the wallet task server and a customized draining tool used to launch the asset theft operation. SlowMist indicates that the first suspicious transfer occurred at 02:31 UTC+8, while the final transfers ended at 05:23, in an operation that lasted approximately three hours and crossed multiple blockchain networks.
Affected Assets and Networks
Bitget halted withdrawals after detecting unauthorized transfers from its hot and warm wallets. The affected assets included ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens, while the transfers extended across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base networks.
CEO Gracy Chen said that the attackers compromised an important backend system within the wallet infrastructure and then used it to falsify transaction data, triggering the authorization mechanism and transferring funds from the compromised hot and warm wallets.
Why Does This Breach Matter?
The incident shows that reliance on third-party security devices does not eliminate the risk of a cascading compromise; access to a security layer surrounding sensitive systems provided the attackers with a starting point toward the wallet servers and then into the financial authorization path. The sequence also highlights the importance of monitoring trusted services, environment variables, and lateral movement, rather than limiting monitoring to the asset wallets themselves.
Chen attributed the attack to North Korean actors based on IP address patterns and on-chain transaction analysis, but the source does not name a specific group. Bitget or the publishing company also did not disclose details of the vulnerabilities or the names of the affected security products. Bitget announced a recovery bounty program offering 5% to anyone who helps recover or freeze the stolen funds.