Close Menu
EmpresernceMag
  • News
  • Us
  • World
  • Technology
  • Crypto
  • Money
    • Business and Market Watch
  • Career
  • Politics
  • Health/Wellness
    • Fitness
  • More
    • State of Women
    • Science/Tech
    • Relationships
    • Sports

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Christa Pike seeks firing squad, not lethal injection: Inside US executions | Death Penalty News

October 1, 2026

Fed Rate Hike: Proven Money Moves for Women Founders

October 1, 2026

iOS 27.2 adds new Messages feature that’s already a favorite

October 1, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram Vimeo
EmpresernceMag
Login
  • News
  • Us
  • World
  • Technology
  • Crypto
  • Money
    • Business and Market Watch
  • Career
  • Politics
  • Health/Wellness
    • Fitness
  • More
    • State of Women
    • Science/Tech
    • Relationships
    • Sports
EmpresernceMag
  • News
  • Us
  • World
  • Technology
  • Crypto
  • Money
  • Career
  • Politics
  • Health/Wellness
  • More
Home » Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Crypto

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Tracy LeeBy Tracy LeeOctober 1, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
Bitget Confirms Third Party Zero Day Behind $387.5 Million Cryptocurrency Theft
Share
Facebook Twitter LinkedIn Pinterest Email

Bitget Confirms $387.5 Million Theft Linked to Security Flaw

On September 24, 2026, Bitget, a prominent cryptocurrency exchange, revealed a significant security breach that resulted in the theft of $387.5 million. The attackers took advantage of a zero-day vulnerability found in third-party security products, as identified by ongoing investigations led by the security firm SlowMist.

Incident Overview

Following the breach, Bitget briefly halted all withdrawals to ensure user assets were safeguarded. During this period, approximately $1.1 million in various cryptocurrencies were identified and frozen by well-known companies such as Circle and Tether.

Exploitation of Vulnerabilities

Bitget’s in-depth analysis indicated that the attackers leveraged the security flaw to gain access to sensitive internal credentials, utilizing them to issue fraudulent withdrawal commands. This enabled them to execute transactions that circumvented established risk management controls.

Affected Assets and Blockchains

The security incident extended across 11 different blockchains, impacting a variety of digital assets, including:

  • XRP
  • ETH
  • USDT
  • ZEC
  • ATOM
  • USDC
  • BNB
  • AVAX
  • TRX
  • ALGO
  • TIA

Timeline of Events

The earliest signs of malicious activity were detected by SlowMist on August 31, 2026, with the exploit tied to a specific node running an affected security service. Investigations indicated that the attackers employed a “hidden script” to extract critical database information, which facilitated unauthorized access.

Development of Malicious Tools

On September 23 and September 25, instances of similar hidden-script activities were recorded. By September 25, the intruders managed to utilize internal credentials to access Bitget’s management platform for a second product, attempting to modify server configurations and upload more malicious files.

Investigation Findings

A critical aspect uncovered during the investigation involved the use of a customized tool designed specifically for the wallet system’s withdrawal mechanism. This tool was responsible for initiating the unauthorized transfers, beginning its operation around 01:49 AM on September 25, 2026.

Advanced Security Breach Techniques

The investigation conducted by Mandiant highlighted how the attackers compromised third-party security appliances to infiltrate Bitget’s wallet environment. Deploying a web shell on a critical security appliance, they established control and subsequently distributed malicious packages across the network.

Attribution of the Attack

Current evidence points towards the involvement of North Korean threat actors in this incident, as suggested by analysis from blockchain security firms Elliptic and TRM Labs. Investigators noted wallet overlaps linked to the laundering of proceeds from previous cyberattacks.

Conclusion

The breach at Bitget highlights the ongoing vulnerabilities present within digital asset exchanges and the importance of robust cybersecurity measures. The exchange has since notified its affected third-party vendor and has disabled compromised functionalities while securing user assets.

Bitget Confirms Cryptocurrency Million Theft ThirdParty ZeroDay
Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleVirginia Women’s Stroke Play: Lauren Greenlief defends Mid-Amateur title, ties VSGA record
Next Article FIRST SET GOES TO ALEX! 💪🏻 Alex Eala takes the first set, 6-3, against China’s Xiyu Wang in the women’s tennis singles semifinals of the 20th Asian Games in Japan on Thursday. (Screenshots/ONE Sports) – facebook.com
Tracy
Tracy Lee

Related Posts

Trump Losing Midterms Could Be the ‘Trigger’ that Pops AI Bubble, Says Market Analyst — Here’s What Crypto Punters Think

October 1, 2026

Current price of Ethereum for Sept. 30, 2026

October 1, 2026

Bitcoin Jumps on Cool PCE Inflation Data as Bond Yields Hit 20-Year Highs

October 1, 2026

Amazon Is Deploying AI to Spy on Its Workers and Bust Unions Before They Form

October 1, 2026
Top Articles

Wicker Park Gym Incident: Two Women Accused of Credit Card Theft and Threats

August 30, 2025

Man Charged in Nighttime Kidnapping Attempts of Two Women

June 2, 2025

A Celebration of Love and Freedom

June 25, 2025

35% of Cornell undergraduate women reported having been sexually assaulted: Survey

September 30, 2026
Don't Miss
News

Christa Pike seeks firing squad, not lethal injection: Inside US executions | Death Penalty News

By Brenda YoungOctober 1, 20260

Recent attempts to execute Christa Gail Pike in Tennessee have drawn significant media attention after…

Fed Rate Hike: Proven Money Moves for Women Founders

October 1, 2026

iOS 27.2 adds new Messages feature that’s already a favorite

October 1, 2026

Cornell student’s 2024 statement to police reveals new details about the night of her alleged rape

October 1, 2026

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

About Us
About Us

Welcome to Empresence Mag, a news and lifestyle destination created to empower, inform, and inspire women around the world. Our mission is to provide a platform that highlights the stories, insights, and issues that matter most to women today.

Don't Miss

Christa Pike seeks firing squad, not lethal injection: Inside US executions | Death Penalty News

October 1, 2026

Fed Rate Hike: Proven Money Moves for Women Founders

October 1, 2026

iOS 27.2 adds new Messages feature that’s already a favorite

October 1, 2026
New Comments
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 EmpresenceMag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Sign In or Register

    Welcome Back!

    Login to your account below.

    Lost password?