Bitget confirms $387.5M theft came via zero-day in third-party security tools
Bitget disclosed that attackers who stole $387.5 million from its hot and warm wallets last week gained access by exploiting zero-day vulnerabilities in two third-party security appliances. Investigations by SlowMist and Mandiant found the attackers planted a web shell and malware, moved laterally to Bitget's production wallet job server, and used a custom withdrawal tool to execute transfers over roughly three hours starting September 24-25. Bitget had suspended withdrawals after detecting the unauthorized transfers.
GoKawiil's interpretation of the reporting above, not reported fact.
The incident shows that even exchanges with strong internal security can be compromised through vulnerabilities in the third-party tools they rely on, widening the attack surface beyond an exchange's own code. Forensic timelines suggesting attacker access as early as August 31 imply the intrusion went undetected for weeks, which could raise questions about monitoring practices industry-wide.
- Attackers exploited zero-day flaws in two third-party security appliances, not Bitget's own infrastructure directly.
- Malicious activity reportedly began as early as August 31, weeks before the theft was executed.
- The theft itself spanned nearly three hours across multiple blockchains before withdrawals were suspended.
YubiKey 5 Series Security Key — With zero-day exploits and stolen credentials at the heart of this breach, hardware-backed authentication like a YubiKey adds a physical layer of defense that malware and phished passwords can't bypass. It's a practical step anyone managing crypto wallets, exchanges, or sensitive admin accounts can take right now to reduce exposure to these kinds of attacks.
See YubiKey 5 Series Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-09-30
Published there as: “Bitget hacked via zero-day in third-party security products”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.