Bitget Hacked: $387.5 Million Stolen via Zero-Day Flaw in Third-Party Security Products
Cryptocurrency exchange Bitget has confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, according to ongoing investigation findings from SlowMist.
The incident, which occurred on September 24, 2026, prompted Bitget to halt all withdrawals temporarily and resulted in close to $632,700 in cryptocurrency assets being frozen by Circle, Tether, and NEAR Intents.
A thorough analysis of the attack has revealed that the attackers exploited a zero-day vulnerability to obtain high-level internal credentials and use them to issue fraudulent withdrawal commands to the wallet system.