Skip to content

Security2 publishers2 min readPublished

Bitget's $387.5 million theft began with zero-days in two of its security appliances

Bitget says attackers stole $387.5 million after exploiting zero-days in two third-party security appliances. Investigators say the appliances' privileged access led the attacker to its production wallet server.

The Watch · Security desk

Illustration accompanying Bitget's $387.5 million theft began with zero-days in two of its security appliances

What happened

  • A custom withdrawal tool the attackers placed on Bitget's systems launched the theft after midnight on September 25.
  • SlowMist timed the first theft transfer at 02:31 UTC+8 and the last at 05:23, a run of nearly three hours across several blockchains.
  • Stolen assets included ETH, XRP, BNB, AVAX, USDT and USDC, moved on chains including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base.
  • CEO Gracy Chen blamed North Korean hackers, citing IP behavior patterns and on-chain analysis.
  • Bitget has opened a Recovery Bounty Program paying 5% to anyone who helps recover or freeze the stolen funds.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Other operators of the same two appliances cannot check for this entry point until Bitget, its investigators or the vendors name the products and the flaws.
  • constraint On Chen's account, approval checks further down the chain cannot catch a withdrawal forged in the backend system that feeds them data.
  • decision Exchanges running security appliances that hold database credentials or can reach wallet servers now have to decide whether to patch and monitor them as closely as the wallet servers.
  • cost If the bounty program recovered the whole sum, Bitget would pay out about $19.4 million.

On SlowMist's account, the first foothold was a service on a Product A node hit by a zero-day [4]. The attacker "ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database," SlowMist said [4]. The same hidden-script activity appeared on two more nodes on September 23 and September 25 [16].

Appliance B was the route to the wallets. The attacker planted a web shell on it and opened a Command-and-Control connection, according to Mandiant [7]. "Using the persistent access on security appliance B, the threat actor moved laterally to Bitget's production wallet job server and deployed malicious packages," Mandiant said [7]. Chief executive Gracy Chen said the attackers breached a critical backend system in the wallet infrastructure and used it to spoof transaction data [12]. The spoofed data triggered Bitget's own authorization process to move funds out of the compromised wallets [12].

The two firms date the intrusion differently. SlowMist's earliest entry in the available logs is August 31 [5]. Mandiant puts the privileged access to appliances A and B on September 24, 2026 [6]. The two dates are 24 days apart [1]. The excerpts identify the products only as "Product A" and "appliances A and B" [4][6]. If SlowMist's date is right, the attacker was active on a Product A node 25 days before the theft began [2].

Mandiant's published excerpt calls the intruder "a threat actor" and does not name a country [6]. According to BleepingComputer, North Korean hackers were behind the Bybit theft, which took $1.5 billion from that exchange's ETH cold wallet [13]. Bitget's losses came from hot and warm wallets [9].

A Bitget spokesperson was not immediately available when BleepingComputer asked for more on the zero-day and the affected products [15].

What to watch

  • Disclosure of the two appliance vendors and the zero-day flaws by Bitget, SlowMist, Mandiant or the vendors themselves.
  • A reconciled timeline from SlowMist and Mandiant on when the attacker first reached the appliances.
  • Amounts frozen or recovered under the bounty program, and whether any investigator beyond Chen backs the North Korea attribution.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories