Security2 publishers2 min readPublished
Bitget's $387.5 million theft began with zero-days in two of its security appliances
Bitget says attackers stole $387.5 million after exploiting zero-days in two third-party security appliances. Investigators say the appliances' privileged access led the attacker to its production wallet server.
The Watch · Security desk

What happened
- A custom withdrawal tool the attackers placed on Bitget's systems launched the theft after midnight on September 25.
- SlowMist timed the first theft transfer at 02:31 UTC+8 and the last at 05:23, a run of nearly three hours across several blockchains.
- Stolen assets included ETH, XRP, BNB, AVAX, USDT and USDC, moved on chains including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base.
- CEO Gracy Chen blamed North Korean hackers, citing IP behavior patterns and on-chain analysis.
- Bitget has opened a Recovery Bounty Program paying 5% to anyone who helps recover or freeze the stolen funds.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Other operators of the same two appliances cannot check for this entry point until Bitget, its investigators or the vendors name the products and the flaws.
- constraint On Chen's account, approval checks further down the chain cannot catch a withdrawal forged in the backend system that feeds them data.
- decision Exchanges running security appliances that hold database credentials or can reach wallet servers now have to decide whether to patch and monitor them as closely as the wallet servers.
- cost If the bounty program recovered the whole sum, Bitget would pay out about $19.4 million.
On SlowMist's account, the first foothold was a service on a Product A node hit by a zero-day [4]. The attacker "ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database," SlowMist said [4]. The same hidden-script activity appeared on two more nodes on September 23 and September 25 [16].
Appliance B was the route to the wallets. The attacker planted a web shell on it and opened a Command-and-Control connection, according to Mandiant [7]. "Using the persistent access on security appliance B, the threat actor moved laterally to Bitget's production wallet job server and deployed malicious packages," Mandiant said [7]. Chief executive Gracy Chen said the attackers breached a critical backend system in the wallet infrastructure and used it to spoof transaction data [12]. The spoofed data triggered Bitget's own authorization process to move funds out of the compromised wallets [12].
The two firms date the intrusion differently. SlowMist's earliest entry in the available logs is August 31 [5]. Mandiant puts the privileged access to appliances A and B on September 24, 2026 [6]. The two dates are 24 days apart [1]. The excerpts identify the products only as "Product A" and "appliances A and B" [4][6]. If SlowMist's date is right, the attacker was active on a Product A node 25 days before the theft began [2].
Mandiant's published excerpt calls the intruder "a threat actor" and does not name a country [6]. According to BleepingComputer, North Korean hackers were behind the Bybit theft, which took $1.5 billion from that exchange's ETH cold wallet [13]. Bitget's losses came from hot and warm wallets [9].
A Bitget spokesperson was not immediately available when BleepingComputer asked for more on the zero-day and the affected products [15].
What to watch
- Disclosure of the two appliance vendors and the zero-day flaws by Bitget, SlowMist, Mandiant or the vendors themselves.
- A reconciled timeline from SlowMist and Mandiant on when the attacker first reached the appliances.
- Amounts frozen or recovered under the bounty program, and whether any investigator beyond Chen backs the North Korea attribution.