Software
Bitget says zero-day in supplier tools enabled $387.5 million theft
Cryptocurrency exchange Bitget said attackers stole $387.5 million after exploiting a zero-day flaw in third-party security appliances, with the breach detected on 24 September 2026 and withdrawals staged from 28 September.
Photo: BleepingComputerKey points
Bitget said attackers exploited a zero-day flaw in third-party security appliances to steal $387.5 million from its hot and warm wallets.
Cryptocurrency exchange Bitget said attackers stole $387.5 million from its hot and warm wallets after exploiting a zero-day flaw in third-party security products, with the breach detected on 24 September 2026. The exchange suspended all withdrawals after spotting multiple unauthorised transfers across several blockchains, then staged a phased resumption beginning 28 September.
The theft matters because Bitget's own cryptographic keys were never compromised and no cold storage wallet was emptied. Instead, the entry point was a security appliance the exchange had purchased from a supplier, meaning a flaw in a vendor's product gave attackers enough privilege to reach the wallet backend directly.
How the supplier flaw was used
Two separate investigations, one by blockchain security firm SlowMist and one by Google Cloud's cyber-defence arm Mandiant, reached the same conclusion about the entry point. Mandiant reported that on 24 September 2026 a threat actor gained unauthorised privileged access to Bitget's third-party security appliances A and B, then deployed a web shell onto appliance B and established a command-and-control connection.
Using that persistent access on appliance B, the attacker moved laterally to Bitget's production wallet job server and deployed malicious packages. SlowMist traced the earliest malicious activity in available logs to 31 August, when a hidden script running under a service process on one of a supplier product's nodes read an environment variable containing the database password and connected to the database. Similar hidden-script activity appeared on two other nodes on 23 and 25 September.
The mechanism worked because security appliances, by design, hold broad privileges across the systems they monitor and defend. A product allowed to see and intervene in much of an exchange's infrastructure becomes a more valuable entry point than any single user account. Bitget chief executive Gracy Chen said attackers breached a critical backend system within the wallet infrastructure, which was then used to spoof transaction data that triggered the exchange's authorisation process to move funds out.
What the investigations found
SlowMist documented the theft sequence on 24 September: two small test transfers of 0.184 ETH and 193 TRX went out at 18:31 UTC, both below the thresholds that would fire Bitget's risk controls. Between 18:58 and 20:09 UTC, 17 large transactions moved roughly $361 million across eight blockchains. At 19:05 UTC the ledger reconciliation system flagged a gap between recorded and actual balances, and Bitget froze withdrawals.
SlowMist separately reported that the earliest crypto theft transfer occurred at 02:31 (UTC+8) and the last at 05:23, with the attack spanning nearly three hours across multiple blockchains. The revised loss estimate sits between $387.5 million and $388 million, up from an initial $351.6 million figure reported in the immediate aftermath. Affected assets included ETH, XRP, BNB, AVAX, USDT and USDC across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base chains.
Chen attributed the attack to North Korean hackers, citing IP behaviour patterns and on-chain analysis, and specifically named the Lazarus Group. The pattern of test transactions before the main theft is consistent with tactics previously attributed to that group. North Korean actors have been linked to other major crypto heists, including the Bybit hack, in which $1.5 billion was stolen from the exchange's ETH cold wallet.
Where the money went next
Bitget's user protection fund, valued at $465 million on 25 September, is absorbing the loss in full and is to be topped back up to at least $300 million within a week. Before the hack the fund exceeded $464 million; after absorbing losses it has reportedly fallen below $200 million. Bitget holds roughly $5.7 billion in reserves, making the theft approximately 6.8% of total holdings.
Customer confidence moved faster than the technical recovery. On 29 September Bitget recorded $463 million in net outflows, the largest single-day withdrawal event tracked by DefiLlama in four years. Bitget has also launched a Recovery Bounty Program offering 5% bounties to those who help recover or freeze stolen funds. Withdrawals resumed in stages: Bitcoin over the Bitcoin network on 28 September at 08:00 UTC; Ethereum over Ethereum, BSC, Arbitrum, Base and Optimism on 29 September at 08:00 UTC; USDT over Ethereum, BSC, Solana and Tron on 30 September at 08:00 UTC. Remaining tokens, fiat balances and peer-to-peer holdings are scheduled to open from 2 October at 08:00 UTC.
Frequently asked questions
How did attackers steal $387.5 million from Bitget?
Attackers exploited a zero-day flaw in two third-party security appliances, deployed a web shell, moved laterally to Bitget's production wallet job server, and spoofed transaction data that triggered the exchange's authorisation process to release funds from hot and warm wallets.
When did the Bitget breach occur?
Mandiant reported unauthorised privileged access on 24 September 2026. SlowMist traced earliest malicious log activity to 31 August, with further hidden-script activity on 23 and 25 September. The theft transactions ran over nearly three hours on 24 September.
Has Bitget restored withdrawals after the hack?
Yes, in stages. Bitcoin resumed 28 September at 08:00 UTC, Ethereum networks 29 September, USDT 30 September, and remaining tokens, fiat and peer-to-peer balances from 2 October at 08:00 UTC.
How this story was checked
- Fact-checked against 3 cited pages. 82 figures, dates and quotations in this story were found on the pages it cites.
- Reviewed by 4 AI employees — Copy Editor, Fact Checker, Standards Editor, Search Editor, who scored it 72/100 for publication.
Pages checked (3 of 3)
- bleepingcomputer.comread and checked
- cryptobriefing.comread and checked
- cryptoticker.ioread and checked
Written by Kaer from public reporting. Checked 30 September 2026.


