Cybersecurity

Bitget Hack Reveals Zero-Day Exploitation in Third-Party Security Devices

Bitget revealed that the theft of $387.5 million in crypto assets resulted from the compromise of two third-party security devices using zero-day vulnerabilities. The attack gave the attackers access to the wallet environment and enabled them to deploy malicious tools used to carry out unauthorized transfers.

2026-09-30
3 min read
1 views
certi.news Editorial Team
Bitget Hack Reveals Zero-Day Exploitation in Third-Party Security Devices
Bitget revealed that the attackers who stole $387.5 million on September 25, 2026, managed to compromise its wallet environment by exploiting zero-day vulnerabilities in two third-party security devices. This was according to two separate investigations conducted by blockchain security firm SlowMist and Google Cloud’s cyber defense unit, Mandiant.

The findings show that the breach did not begin directly with Bitget’s wallets, but with external security devices identified in the two investigations as Product A and Product B. Logs recorded the earliest malicious activity on August 31, when the attackers exploited a service running on one of Product A’s nodes and executed an obfuscated script under the service account to read an environment variable containing the database password and connect to it.

From the Vulnerability to the Wallet Environment

According to Mandiant, the attackers obtained elevated and unauthorized privileges on the two security devices on September 24. They then planted a web shell on Device B and established a connection with a command-and-control server. Through this access, they moved laterally to Bitget’s production wallet task server, where they deployed malicious packages.

The investigations also detected malware on the wallet task server and a customized draining tool used to launch the asset theft operation. SlowMist indicates that the first suspicious transfer occurred at 02:31 UTC+8, while the final transfers ended at 05:23, in an operation that lasted approximately three hours and crossed multiple blockchain networks.

Affected Assets and Networks

Bitget halted withdrawals after detecting unauthorized transfers from its hot and warm wallets. The affected assets included ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens, while the transfers extended across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base networks.

CEO Gracy Chen said that the attackers compromised an important backend system within the wallet infrastructure and then used it to falsify transaction data, triggering the authorization mechanism and transferring funds from the compromised hot and warm wallets.

Why Does This Breach Matter?

The incident shows that reliance on third-party security devices does not eliminate the risk of a cascading compromise; access to a security layer surrounding sensitive systems provided the attackers with a starting point toward the wallet servers and then into the financial authorization path. The sequence also highlights the importance of monitoring trusted services, environment variables, and lateral movement, rather than limiting monitoring to the asset wallets themselves.

Chen attributed the attack to North Korean actors based on IP address patterns and on-chain transaction analysis, but the source does not name a specific group. Bitget or the publishing company also did not disclose details of the vulnerabilities or the names of the affected security products. Bitget announced a recovery bounty program offering 5% to anyone who helps recover or freeze the stolen funds.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news