Bitget, a prominent cryptocurrency exchange, recently revealed a significant security breach resulting in the theft of $387.5 million from its hot and warm wallets. The breach was attributed to a zero-day vulnerability in third-party security products, as detailed by the blockchain security firm SlowMist. The attackers exploited this flaw to gain unauthorized access and execute fraudulent withdrawal commands, bypassing existing risk controls. The incident affected 11 blockchains, including Ethereum, XRP Ledger, and Zcash, and involved assets such as XRP, ETH, and USDT.

The breach first came to light on September 24, 2026, when Bitget disclosed the unauthorized transfers and temporarily suspended all withdrawals. Investigations revealed that the attackers used high-level internal credentials to issue the fraudulent commands. In response, Bitget has informed the third-party vendor of the vulnerability and disabled the compromised functionality until a fix is implemented.

SlowMist's analysis traced the malicious activity back to August 31, 2026, with the attackers exploiting a zero-day vulnerability in a service running on Product A's nodes. This allowed them to access sensitive information, including database passwords. Additionally, on September 25, the attackers accessed Product B's management platform using an employee's credentials, injecting system commands to deploy malicious files.

The attackers utilized a custom tool to execute the theft, which was later recovered by SlowMist. This tool was specifically designed to exploit Bitget's wallet system. Further investigations by Mandiant uncovered the use of a web shell on security appliance B, facilitating lateral movement into Bitget's wallet environment. The attackers, believed to be linked to North Korean threat actors, used established IP patterns and on-chain analysis to further their illicit activities.