Bitget Suffers $387.5 Million Cryptocurrency Theft via Zero-Day Exploit
A $387.5 million cryptocurrency theft occurred at Bitget, a major exchange, after attackers exploited a zero-day vulnerability in third-party security products on September 24-25, 2026. The breach was confirmed by Bitget and investigated by SlowMist and Mandiant. The attackers used the zero-day exploit to gain unauthorized access to internal credentials and issued fraudulent withdrawal commands, bypassing existing risk controls and impacting assets across 11 blockchains.
The incident highlights the operational and supply chain risks associated with relying on third-party security tools, especially in high-value environments such as cryptocurrency exchanges. Attribution is assessed as likely North Korean threat actors, based on IP behavior, on-chain analysis, and wallet overlaps with previous attacks.
The attackers exploited a zero-day vulnerability in at least two third-party security appliances, referred to as Product A and Product B. They deployed hidden scripts, extracted environment variables containing database credentials, and escalated their privileges. The attackers then moved laterally to Bitget's production wallet job server, where they deployed malicious packages and used a custom withdrawal tool to automate the theft of assets across multiple blockchains.