Bitget Suffers $387.5 Million Cryptocurrency Theft via Zero-Day Vulnerability
Bitget, a cryptocurrency exchange, suffered a massive hacking incident in September 2026, resulting in the theft of $387.5 million worth of cryptocurrency. The attackers exploited a zero-day vulnerability in a third-party security product used by Bitget to gain access to highly privileged internal credentials.
The hackers then sent fake withdrawal commands to the wallet system, bypassing risk verification and transferring funds to an external source. According to an investigation by SlowMist, the activity related to the attack dates back to August 31, 2026, before the cryptocurrency was stolen.
Bitget has fixed the vulnerability, reset all internal credentials, and strengthened management of high-privilege accounts. The exchange also notified the third-party vendor in question and suspended the affected functions.