Bitget confirms $387.5M theft came via zero-day in third-party security tools
Bitget disclosed that attackers who stole $387.5 million from its hot and warm wallets last week gained access by exploiting zero-day vulnerabilities in two third-party security appliances. Investigations by SlowMist and Mandiant found the attackers planted a web shell and malware, moved laterally to Bitget's production wallet job server, and used a custom withdrawal tool to execute transfers over roughly three hours starting September 24-25. Bitget had suspended withdrawals after detecting the unauthorized transfers.