Cryptocurrency exchange Bitget said attackers stole $387.5 million after exploiting zero-day vulnerabilities in two third-party security appliances. The company said the breach affected its wallet environment.
Investigations by blockchain security firm SlowMist and Google Cloud’s cyber-defense arm Mandiant found that attackers gained access to the appliances and moved to Bitget’s production wallet job server. They placed a web shell on one appliance and malicious packages on the server. The attackers also used a custom withdrawal tool to move cryptocurrency.
SlowMist said the earliest malicious activity found in available logs dated to August 31. It reported similar hidden-script activity on two other nodes on September 23 and September 25. Mandiant said an attacker gained privileged access to the appliances on September 24, 2026.
SlowMist said the theft transfers began at 02:31 (UTC+8) and ended at 05:23, spanning nearly 3 hours across multiple blockchains. Bitget suspended withdrawals after detecting unauthorized transfers from hot and warm wallets. CEO Gracy Chen said multiple assets and blockchain networks were affected, and blamed North Korean hackers, citing IP behavior patterns and on-chain analysis. BleepingComputer said a Bitget spokesperson was not immediately available for comment on the flaw and compromised products.
Bitget has since launched a Recovery Bounty Program offering 5% to those who help recover or freeze the stolen funds.
Comments
0No comments yet. Be the first to comment.