Block Editorial
Block Editorial

Bringing You the Future of the Internet

Features

Bitget Links $387.5 Million Theft To Third-Party Zero-Day

Archival photograph of a speaker at a Bitget Crypto Experience Month event, separate from the theft
Excerpt
Bitget said a third-party zero-day enabled a $387.5 million cryptocurrency theft. SlowMist and Mandiant described compromised security appliances and malicious

Contents

Published
October 4, 2026
Read Time
3 min read
In This Article
Category
Tags

Bitget confirmed that attackers behind a $387.5 million cryptocurrency theft exploited a zero-day flaw in third-party security products. The exchange cited ongoing investigation findings from blockchain security company SlowMist.

The company said attackers obtained high-level internal credentials and issued fraudulent withdrawal commands. Those commands caused abnormal transfers that bypassed existing risk controls, according to the exchange.

Bitget Disables Affected Functionality

According to The Hacker News report, Bitget notified the relevant third-party vendor. The exchange disabled affected functionality while awaiting completion of a fix.

Archival Bitget exhibition booth at TOKEN2049, separate from the theft
Archival Bitget exhibition booth at TOKEN2049, separate from the theft.

The exchange disclosed the $387.5 million theft on September 24, 2026. Unauthorized transfers from hot and warm wallets prompted a temporary halt to all withdrawals.

Close to $1.1 million in cryptocurrency assets have been frozen by Circle, Tether and NEAR Intents, the report said. The incident affected 11 blockchains.

Those networks include Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand and Celestia. Investigators identified affected assets including XRP, ETH, USDT, ZEC, ATOM, USDC and USD0.

Archival group photograph at a Bitget summer event, separate from the theft
Archival group photograph at a Bitget summer event, separate from the theft.

The reported asset list also includes XAUt, BNB, AVAX, TRX, ALGO and TIA. The network and asset lists describe findings identified to date.

SlowMist Traces Earlier Malicious Activity

SlowMist said the earliest malicious activity linked to the attack dated to August 31, 2026. Its progress report described a vulnerable service running on a node belonging to Product A.

The attacker ran a hidden script under the service process, SlowMist said. The script accessed an environment variable containing a database password and connected to the database.

Similar hidden-script activity appeared on two other nodes on September 23 and September 25. SlowMist said the findings indicated compromised service environments before assets were transferred out.

Related security reporting covers unauthorized AI access to systems and defense contractor cybersecurity certification. Those stories concern separate incidents and organizations.

Investigators Describe A Customized Withdrawal Tool

On September 25, 2026, the attacker reportedly accessed another product’s management platform using an internal employee’s identity. Investigators referred to that system as Product B.

SlowMist described three consecutive attempts to inject system commands into task parameters. The attacker sought to write malicious files through those attempts.

The attacker later submitted code through a web execution endpoint, SlowMist said. The attempts included changing server configuration, writing a relay file and assembling malicious program files.

SlowMist also recovered a customized tool among deleted files. The program was tailored to the wallet system’s withdrawal logic.

The company said the tool began executing theft at 01:49 a.m on September 25, 2026. That timing was presented as a finding from its investigation.

Bitget Cites Findings From Multiple Investigators

Mandiant found unauthorized access to third-party security appliances A and B. Investigators said the attackers used that access to move into the exchange’s wallet environment.

The attacker deployed a web shell on appliance B and established a command-and-control connection, Mandiant said. Persistent access enabled movement to the production wallet job server and deployment of malicious packages.

For broader blockchain coverage, related reporting examines post-quantum blockchain signatures.

Bitget said IP behavior and on-chain analysis indicated North Korean threat actors. Elliptic and TRM Labs found wallet overlaps with laundering from previous hacks, while the vendor fix remains pending.

About the Author
administrator

Block Editorial Staff publishes reported coverage and explanatory analysis on cryptocurrency, blockchain, Web3, digital assets and financial technology.

the Latest
Archival photograph of workstations at Rapid7 headquarters in Boston

Rapid7 Launches Intelligence Engine To Counter Automated Attacks

Block Editorial Staff
Students and speakers at the Illuminate 2026 workshop welcome session in Nashik

Illuminate 2026 Brings Startup Workshop To 120 Students

Block Editorial Staff
Archival photograph of a speaker at a Bitget Crypto Experience Month event, separate from the theft

Bitget Links $387.5 Million Theft To Third-Party Zero-Day

Block Editorial Staff