Skip to main content

Bitget hacked via zero-day in third-party security products

0
Critical
Breachzero-day
Published: 09/30/2026 (09/30/2026, 11:11:46 UTC)
Source: Bleeping Computer

Description

Cryptocurrency exchange Bitget suffered a major breach resulting in the theft of $387.5 million. Attackers exploited zero-day vulnerabilities in two third-party security appliances to gain unauthorized privileged access. They deployed web shells and malware to move laterally into Bitget's wallet infrastructure, ultimately compromising hot and warm wallets across multiple blockchain networks. The attack spanned several hours and affected multiple assets including ETH, XRP, BNB, AVAX, USDT, and USDC. Bitget has suspended withdrawals and launched a recovery bounty program. The attackers are attributed to North Korean threat actors based on IP and on-chain analysis.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 11:42:21 UTC

Technical Analysis

Bitget was breached after attackers exploited zero-day vulnerabilities in two third-party security products used as security appliances. The attackers gained privileged access to these appliances, deployed web shells and malware, and moved laterally to Bitget's production wallet job server. They then used a custom withdrawal tool to steal $387.5 million from hot and warm wallets across multiple blockchains including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. The breach was detected after unauthorized transfers were observed, leading to suspension of withdrawals. Investigations by SlowMist and Mandiant confirmed the attack timeline and methods. The attackers are linked to North Korean hacking groups known for previous large-scale crypto thefts.

Potential Impact

The breach resulted in the theft of $387.5 million in cryptocurrency from Bitget's hot and warm wallets. Multiple blockchain assets and networks were affected, causing significant financial loss and operational disruption including suspension of withdrawals. The attackers gained unauthorized privileged access to critical backend systems, enabling them to spoof transaction data and bypass authorization controls. The incident damages Bitget's security posture and trustworthiness in the cryptocurrency exchange market.

Defensive Guidance

No official patch or remediation details for the exploited zero-day vulnerabilities in the third-party security appliances have been disclosed. Bitget has suspended all withdrawals to prevent further unauthorized transfers and launched a Recovery Bounty Program to incentivize recovery or freezing of stolen funds. Organizations using similar third-party security products should monitor vendor advisories closely for patches or mitigations. Until fixes are available, consider isolating or restricting access to critical security appliances and wallet infrastructure to reduce attack surface.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.67,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/","fetched":true,"fetchedAt":"2026-09-30T11:42:16.257Z","wordCount":786}

Threat ID: 6abcf5980df196e1a9f4736d

Added to database: 09/30/2026, 11:42:16 UTC

Last enriched: 09/30/2026, 11:42:21 UTC

Last updated: 09/30/2026, 13:50:34 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses