Bitget confirmed that attackers behind a $387.5 million cryptocurrency theft exploited a zero-day flaw in third-party security products. The exchange cited ongoing investigation findings from blockchain security company SlowMist.
The company said attackers obtained high-level internal credentials and issued fraudulent withdrawal commands. Those commands caused abnormal transfers that bypassed existing risk controls, according to the exchange.
Bitget Disables Affected Functionality
According to The Hacker News report, Bitget notified the relevant third-party vendor. The exchange disabled affected functionality while awaiting completion of a fix.

The exchange disclosed the $387.5 million theft on September 24, 2026. Unauthorized transfers from hot and warm wallets prompted a temporary halt to all withdrawals.
Close to $1.1 million in cryptocurrency assets have been frozen by Circle, Tether and NEAR Intents, the report said. The incident affected 11 blockchains.
Those networks include Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand and Celestia. Investigators identified affected assets including XRP, ETH, USDT, ZEC, ATOM, USDC and USD0.

The reported asset list also includes XAUt, BNB, AVAX, TRX, ALGO and TIA. The network and asset lists describe findings identified to date.
SlowMist Traces Earlier Malicious Activity
SlowMist said the earliest malicious activity linked to the attack dated to August 31, 2026. Its progress report described a vulnerable service running on a node belonging to Product A.
The attacker ran a hidden script under the service process, SlowMist said. The script accessed an environment variable containing a database password and connected to the database.
Similar hidden-script activity appeared on two other nodes on September 23 and September 25. SlowMist said the findings indicated compromised service environments before assets were transferred out.
Related security reporting covers unauthorized AI access to systems and defense contractor cybersecurity certification. Those stories concern separate incidents and organizations.
Investigators Describe A Customized Withdrawal Tool
On September 25, 2026, the attacker reportedly accessed another product’s management platform using an internal employee’s identity. Investigators referred to that system as Product B.
SlowMist described three consecutive attempts to inject system commands into task parameters. The attacker sought to write malicious files through those attempts.
The attacker later submitted code through a web execution endpoint, SlowMist said. The attempts included changing server configuration, writing a relay file and assembling malicious program files.
SlowMist also recovered a customized tool among deleted files. The program was tailored to the wallet system’s withdrawal logic.
The company said the tool began executing theft at 01:49 a.m on September 25, 2026. That timing was presented as a finding from its investigation.
Bitget Cites Findings From Multiple Investigators
Mandiant found unauthorized access to third-party security appliances A and B. Investigators said the attackers used that access to move into the exchange’s wallet environment.
The attacker deployed a web shell on appliance B and established a command-and-control connection, Mandiant said. Persistent access enabled movement to the production wallet job server and deployment of malicious packages.
For broader blockchain coverage, related reporting examines post-quantum blockchain signatures.
Bitget said IP behavior and on-chain analysis indicated North Korean threat actors. Elliptic and TRM Labs found wallet overlaps with laundering from previous hacks, while the vendor fix remains pending.





