Bitget Confirms $387.5 Million Theft Linked to Security Flaw
On September 24, 2026, Bitget, a prominent cryptocurrency exchange, revealed a significant security breach that resulted in the theft of $387.5 million. The attackers took advantage of a zero-day vulnerability found in third-party security products, as identified by ongoing investigations led by the security firm SlowMist.
Incident Overview
Following the breach, Bitget briefly halted all withdrawals to ensure user assets were safeguarded. During this period, approximately $1.1 million in various cryptocurrencies were identified and frozen by well-known companies such as Circle and Tether.
Exploitation of Vulnerabilities
Bitget’s in-depth analysis indicated that the attackers leveraged the security flaw to gain access to sensitive internal credentials, utilizing them to issue fraudulent withdrawal commands. This enabled them to execute transactions that circumvented established risk management controls.
Affected Assets and Blockchains
The security incident extended across 11 different blockchains, impacting a variety of digital assets, including:
- XRP
- ETH
- USDT
- ZEC
- ATOM
- USDC
- BNB
- AVAX
- TRX
- ALGO
- TIA
Timeline of Events
The earliest signs of malicious activity were detected by SlowMist on August 31, 2026, with the exploit tied to a specific node running an affected security service. Investigations indicated that the attackers employed a “hidden script” to extract critical database information, which facilitated unauthorized access.
Development of Malicious Tools
On September 23 and September 25, instances of similar hidden-script activities were recorded. By September 25, the intruders managed to utilize internal credentials to access Bitget’s management platform for a second product, attempting to modify server configurations and upload more malicious files.
Investigation Findings
A critical aspect uncovered during the investigation involved the use of a customized tool designed specifically for the wallet system’s withdrawal mechanism. This tool was responsible for initiating the unauthorized transfers, beginning its operation around 01:49 AM on September 25, 2026.
Advanced Security Breach Techniques
The investigation conducted by Mandiant highlighted how the attackers compromised third-party security appliances to infiltrate Bitget’s wallet environment. Deploying a web shell on a critical security appliance, they established control and subsequently distributed malicious packages across the network.
Attribution of the Attack
Current evidence points towards the involvement of North Korean threat actors in this incident, as suggested by analysis from blockchain security firms Elliptic and TRM Labs. Investigators noted wallet overlaps linked to the laundering of proceeds from previous cyberattacks.
Conclusion
The breach at Bitget highlights the ongoing vulnerabilities present within digital asset exchanges and the importance of robust cybersecurity measures. The exchange has since notified its affected third-party vendor and has disabled compromised functionalities while securing user assets.
