Bitget Hackers Exploit Zero-Day Vulnerability to Steal $387.5 Million
A massive cryptocurrency heist occurred at Bitget in September 2026, resulting in the theft of $387.5 million worth of digital assets.
The attackers exploited a zero-day vulnerability in a third-party security product used by Bitget to gain access to highly privileged internal credentials.
Using these credentials, they sent fake withdrawal commands to the wallet system, bypassing risk verification and transferring cryptocurrency to an external source.
SlowMist investigation revealed that the attackers had been active since August 31, 2026, and had installed a remote control program called a 'Web Shell' on another security product, securing communication with an external command and control server.