Lazarus Group Suspected in Bitget Hack
The recent $387.5 million theft from the Bitget cryptocurrency exchange exposes a critical failure in modern cybersecurity, where defensive infrastructure has become a primary vector for state-sponsored infiltration.
Investigations by SlowMist and Mandiant confirm that the breach did not stem from a failure of the exchange's core blockchain logic but from a zero-day exploit targeting two third-party security appliances.
The attack was a methodical, long-term operation, with malicious activity dating back to August 31, 2026. The threat actors gained unauthorized privileged access to the third-party security appliances on September 24 and subsequently dropped web shells on one of the devices.
This foothold allowed them to pivot to the production wallet job server, where they deployed custom malware and a withdrawal tool designed to execute fraudulent commands while bypassing existing risk controls.