Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget suffered a major breach resulting in the theft of $387.5 million. Attackers exploited zero-day vulnerabilities in two third-party security appliances to gain unauthorized privileged access. They deployed web shells and malware to move laterally into Bitget's wallet infrastructure, ultimately compromising hot and warm wallets across multiple blockchain networks. The attack spanned several hours and affected multiple assets including ETH, XRP, BNB, AVAX, USDT, and USDC. Bitget has suspended withdrawals and launched a recovery bounty program. The attackers are attributed to North Korean threat actors based on IP and on-chain analysis.
AI Analysis
Technical Summary
Bitget was breached after attackers exploited zero-day vulnerabilities in two third-party security products used as security appliances. The attackers gained privileged access to these appliances, deployed web shells and malware, and moved laterally to Bitget's production wallet job server. They then used a custom withdrawal tool to steal $387.5 million from hot and warm wallets across multiple blockchains including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. The breach was detected after unauthorized transfers were observed, leading to suspension of withdrawals. Investigations by SlowMist and Mandiant confirmed the attack timeline and methods. The attackers are linked to North Korean hacking groups known for previous large-scale crypto thefts.
Potential Impact
The breach resulted in the theft of $387.5 million in cryptocurrency from Bitget's hot and warm wallets. Multiple blockchain assets and networks were affected, causing significant financial loss and operational disruption including suspension of withdrawals. The attackers gained unauthorized privileged access to critical backend systems, enabling them to spoof transaction data and bypass authorization controls. The incident damages Bitget's security posture and trustworthiness in the cryptocurrency exchange market.
Mitigation Recommendations
No official patch or remediation details for the exploited zero-day vulnerabilities in the third-party security appliances have been disclosed. Bitget has suspended all withdrawals to prevent further unauthorized transfers and launched a Recovery Bounty Program to incentivize recovery or freezing of stolen funds. Organizations using similar third-party security products should monitor vendor advisories closely for patches or mitigations. Until fixes are available, consider isolating or restricting access to critical security appliances and wallet infrastructure to reduce attack surface.
Bitget hacked via zero-day in third-party security products
Description
Cryptocurrency exchange Bitget suffered a major breach resulting in the theft of $387.5 million. Attackers exploited zero-day vulnerabilities in two third-party security appliances to gain unauthorized privileged access. They deployed web shells and malware to move laterally into Bitget's wallet infrastructure, ultimately compromising hot and warm wallets across multiple blockchain networks. The attack spanned several hours and affected multiple assets including ETH, XRP, BNB, AVAX, USDT, and USDC. Bitget has suspended withdrawals and launched a recovery bounty program. The attackers are attributed to North Korean threat actors based on IP and on-chain analysis.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Bitget was breached after attackers exploited zero-day vulnerabilities in two third-party security products used as security appliances. The attackers gained privileged access to these appliances, deployed web shells and malware, and moved laterally to Bitget's production wallet job server. They then used a custom withdrawal tool to steal $387.5 million from hot and warm wallets across multiple blockchains including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. The breach was detected after unauthorized transfers were observed, leading to suspension of withdrawals. Investigations by SlowMist and Mandiant confirmed the attack timeline and methods. The attackers are linked to North Korean hacking groups known for previous large-scale crypto thefts.
Potential Impact
The breach resulted in the theft of $387.5 million in cryptocurrency from Bitget's hot and warm wallets. Multiple blockchain assets and networks were affected, causing significant financial loss and operational disruption including suspension of withdrawals. The attackers gained unauthorized privileged access to critical backend systems, enabling them to spoof transaction data and bypass authorization controls. The incident damages Bitget's security posture and trustworthiness in the cryptocurrency exchange market.
Defensive Guidance
No official patch or remediation details for the exploited zero-day vulnerabilities in the third-party security appliances have been disclosed. Bitget has suspended all withdrawals to prevent further unauthorized transfers and launched a Recovery Bounty Program to incentivize recovery or freezing of stolen funds. Organizations using similar third-party security products should monitor vendor advisories closely for patches or mitigations. Until fixes are available, consider isolating or restricting access to critical security appliances and wallet infrastructure to reduce attack surface.
Technical Details
- Classification
- {"confidence":0.67,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/","fetched":true,"fetchedAt":"2026-09-30T11:42:16.257Z","wordCount":786}
Threat ID: 6abcf5980df196e1a9f4736d
Added to database: 09/30/2026, 11:42:16 UTC
Last enriched: 09/30/2026, 11:42:21 UTC
Last updated: 09/30/2026, 13:50:34 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.