MikhbarMIKHBAR
Cybersecurity

Bitget Reveals Hack Caused by Third-Party Zero-Day

Cryptocurrency exchange Bitget has disclosed that a major security breach resulting in the theft of $387.5 million was carried out using zero-day flaws in third-party security products.

Bitget Reveals Hack Caused by Third-Party Zero-Day

Investigation Findings on the Third-Party Zero-Day

Cryptocurrency exchange Bitget revealed that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. According to Bitget, two separate investigations by blockchain security firm SlowMist and Google Cloud's cyber-defense arm Mandiant indicated that the threat actors accessed Bitget's wallet environment after compromising two security appliances with zero-day exploits. Detailed insights from these investigations are available via SlowMist said and Mandiant added.

Following the breach, the attackers dropped web shells on one of the hacked appliances and malware on the crypto exchange's production wallet job server. They also introduced a custom withdrawal tool used to launch the cryptocurrency theft after midnight on September 25. According to reports, the earliest crypto theft transfer occurred at 02:31 (UTC+8) and the last took place at 05:23, with the attack spanning nearly 3 hours across multiple blockchains.

Execution of the Attack and Compromised Systems

The earliest malicious activity identified in available logs dates back to August 31, when a service running on one of the product's nodes was affected by a zero-day vulnerability. The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database. Similar hidden-script activity was observed on two other nodes on September 23 and September 25.

Forensic findings further indicate that on September 24, 2026, a threat actor gained unauthorized privileged access to Bitget's third-party security appliances A and B. The threat actor deployed a web shell onto security appliance B and established a Command-and-Control connection. Utilizing persistent access on security appliance B, the actor moved laterally to Bitget's production wallet job server and deployed malicious packages.

Impact on Assets and Attribution to North Korean Hackers

Bitget suspended all withdrawals on Thursday after detecting multiple unauthorized transfers from its hot and warm crypto wallets, discovering that attackers had stolen $387.5 million from them. CEO Gracy Chen noted the incident affected multiple assets, including ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens. The exploit involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains.

Chen also blamed the attack on North Korean hackers, citing IP behavior patterns and on-chain analysis as evidence. She added that they breached a critical backend system within Bitget's wallet infrastructure that was later used to spoof transaction data, triggering the exchange's authorization process to move funds out of compromised hot and warm wallets. Additional reporting on the scale of these thefts can be found regarding the fact that attackers had stolen $387.5 million.

North Korean hackers have been linked to numerous major cryptocurrency heists. Notably, a similar group was involved in the Bybit hack, in which attackers stole $1.5 billion from the crypto exchange's Ethereum cold wallet.

Response and Recovery Bounty Program

Since the breach, Bitget has launched a Recovery Bounty Program that offers bounties of 5% to individuals who help recover or freeze funds stolen in the attack. Further details regarding the initiative have been officially published by Bitget.

A Bitget spokesperson was not immediately available when BleepingComputer contacted them earlier for more information on the zero-day flaw and the third-party security products compromised in the attack. Investigations into the incident remain ongoing across multiple security firms.

Sources

Continue chronologically