Security & privacy

Bitget hack traced to zero-day in third-party security tools

Attackers stole $387.5 million from Bitget by exploiting a zero-day vulnerability in external security appliances and using custom malware to bypass withdrawal controls.

Cryptocurrency exchange Bitget confirmed that the theft of $387.5 million in late September 2026 was enabled by a zero-day vulnerability in third-party security products. The breach, attributed to North Korean threat actors, involved lateral movement from compromised security appliances into the exchange’s core wallet infrastructure.

What happened

On September 24, 2026, Bitget disclosed that unauthorized transfers had drained its hot and warm wallets, prompting an immediate halt on all withdrawals. Subsequent investigations by blockchain security firm SlowMist and Google-owned Mandiant revealed that the attackers had been active since at least August 31, 2026. The initial entry point was a zero-day flaw in a service running on nodes of a third-party security product, referred to as Product A. This vulnerability allowed the attackers to execute hidden scripts, read environment variables containing database passwords, and establish persistent access.

The compromise deepened on September 25, 2026, when the threat actors targeted a second third-party tool, Product B. Using stolen internal employee credentials, they injected system commands into the product’s task parameters via its management platform. This allowed them to modify server configurations, upload malicious files, and deploy a web shell. From this foothold, they moved laterally to Bitget’s production wallet job server, where they deployed custom malware designed specifically to bypass existing risk controls and initiate fraudulent withdrawals.

The attack impacted assets across 11 blockchains, including Ethereum, TRON, BNB Smart Chain, and Solana-based networks like Base and Optimism. Stolen tokens included ETH, USDT, USDC, XRP, and BNB. While the total loss stands at $387.5 million, stablecoin issuers Circle and Tether, along with NEAR Intents, have frozen approximately $1.1 million of the illicit funds. Bitget has disabled the affected third-party functionalities and is working with vendors to patch the vulnerabilities.

How it works

The attack chain relied on supply chain compromise rather than direct exploitation of Bitget’s primary application code. The attackers first exploited a zero-day vulnerability in Product A, a security appliance intended to protect the network. By running scripts under the service process, they extracted sensitive credentials from environment variables, a common but risky practice for storing secrets. This gave them database access and a foothold within the trusted security perimeter.

Once inside, the attackers used Product B’s management interface to escalate privileges. By injecting commands into task parameters, they bypassed standard input validation and wrote malicious files directly to the server. This technique allowed them to establish a Command-and-Control (C2) connection and deploy a bespoke tool tailored to Bitget’s withdrawal logic. The malware executed at 01:49 a.m. on September 25, initiating transfers that appeared legitimate to basic monitoring systems but violated deeper behavioral risk rules.

Key details

  • The total value of stolen assets is $387.5 million, with activity dating back to August 31, 2026.
  • Attackers exploited zero-day vulnerabilities in two third-party security products, labeled Product A and Product B.
  • The breach impacted 11 blockchains, including Ethereum, Arbitrum, Optimism, Base, and BNB Smart Chain.
  • Custom malware was used to bypass risk controls and execute unauthorized withdrawals from hot and warm wallets.
  • Approximately $1.1 million in assets have been frozen by Circle, Tether, and NEAR Intents.
  • Forensic analysis by Elliptic and TRM Labs links the attack to North Korean threat actors based on wallet overlaps.

Why it matters

This incident highlights the critical risk posed by third-party security tools themselves. Organizations often treat security appliances as trusted components, granting them high-level access to internal networks and databases. When these tools contain unpatched zero-day vulnerabilities, they become ideal entry points for attackers seeking to bypass perimeter defenses. For engineering teams, this underscores the need to apply the same rigorous security standards to vendor software as to internal code, including strict isolation and minimal privilege access.

The use of custom malware to bypass risk controls also demonstrates the sophistication of modern financial cybercrime. Standard monitoring systems may fail to detect anomalies if the attacker understands the internal logic of the transaction system. This suggests that static rule-based security is insufficient against targeted attacks. Developers and security leads must implement behavioral analysis and multi-layered verification for high-value operations, ensuring that no single component failure can lead to catastrophic loss.

What you can do

  • Audit all third-party security tools for excessive permissions and isolate them from critical production environments.
  • Avoid storing sensitive credentials in environment variables; use dedicated secret management solutions with strict access controls.
  • Implement rigorous input validation on all management interfaces and API endpoints to prevent command injection attacks.
  • Deploy behavioral anomaly detection for financial transactions, focusing on deviation from normal patterns rather than just static thresholds.
  • Conduct regular red team exercises that specifically target supply chain and third-party vendor integration points.
  • Ensure that withdrawal processes require multi-party approval and out-of-band verification for large or unusual transfers.

Tools from the Bytechap store

Keep reading

All stories