In a recent disclosure, cryptocurrency exchange Bitget has confirmed that a zero-day vulnerability in third-party security products was exploited by attackers to steal $387.5 million. The breach, which occurred last week, was detailed in findings from security firm SlowMist, underscoring the sophisticated methods employed by the perpetrators.
Details of the Security Breach
The incident was first brought to light on September 24, 2026, when Bitget reported unauthorized transfers from its hot and warm wallets, prompting a halt on all withdrawals. Investigations have revealed that attackers used a zero-day flaw to gain high-level access, allowing them to execute fake withdrawal commands. Affected cryptocurrency assets, totaling approximately $632,700, have since been frozen by Circle, Tether, and NEAR Intents.
Bitget’s analysis highlighted the attackers’ strategy of exploiting internal credentials to initiate abnormal transfers, circumventing existing risk controls. In response, the company has informed the third-party vendor of the breach and has deactivated the compromised functionality until a fix can be implemented.
Impact Across Multiple Blockchains
The security breach impacted 11 blockchains, including Ethereum, XRP Ledger, and others. A wide range of assets have been affected, such as XRP, ETH, USDT, and BNB. SlowMist’s report traced the attack back to August 31, 2026, identifying the zero-day vulnerability within a service running on a node of a third-party product.
The report further uncovered that attackers managed to run hidden scripts to access sensitive database passwords, leading to a compromise of the service environment well before the unauthorized asset transfers occurred.
Advanced Tactics and Attribution
On September 25, 2026, the attackers gained access to a management platform using an employee’s credentials, injecting system commands to execute malicious activities. They submitted code to alter server configurations and introduced a custom tool for asset siphoning, which was later recovered by SlowMist.
Further investigations by Google-owned Mandiant revealed that the attackers breached third-party security appliances to infiltrate Bitget’s wallet systems. They installed a web shell and established a Command-and-Control connection, facilitating lateral movement within Bitget’s infrastructure to deploy malicious packages.
Bitget, along with cybersecurity firms Elliptic and TRM Labs, has attributed the attack to North Korean threat actors. On-chain analysis and IP behavior patterns have linked the heist to known wallet addresses used in previous illicit operations.
The incident highlights the critical need for enhanced security measures and prompt vulnerability management to protect cryptocurrency exchanges from sophisticated cyber-attacks. Bitget continues to work closely with security experts to address the vulnerabilities and prevent future breaches.
