Bitget Hacked via Zero-Day Exploit in Third-Party Security Products
Bitget, a major cryptocurrency exchange, was hit with a massive $387.5 million theft after attackers exploited a zero-day vulnerability in third-party security products on September 24-25, 2026. The breach was confirmed by Bitget and independently investigated by blockchain security firm SlowMist and Google-owned Mandiant.
The attackers gained unauthorized access to internal credentials and issued fraudulent withdrawal commands, bypassing existing risk controls and impacting assets across 11 blockchains, including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia.
The incident highlights the operational and supply chain risks associated with relying on third-party security tools, especially in high-value environments such as cryptocurrency exchanges. Attribution is assessed as likely North Korean threat actors, based on IP behavior, on-chain analysis, and wallet overlaps with previous attacks.
Law enforcement and regulatory responses included the freezing of $1.1 million in assets by Circle, Tether, and NEAR Intents. The attackers demonstrated advanced capabilities, including the exploitation of a zero-day vulnerability, deployment of hidden scripts and web shells, credential theft, lateral movement, and the use of a custom withdrawal tool.