Cryptocurrency exchange Bitget has officially confirmed that the massive security breach last week resulting in the theft of $387.5 million was facilitated by zero-day vulnerabilities in third-party security products. The confirmation follows ongoing, comprehensive investigation findings released by blockchain security firm SlowMist, shedding further light on one of the most sophisticated cyber heists targeting digital asset platforms in recent memory.

In a formal statement shared via a post on the social media platform X, Bitget detailed the latest insights from the probe. The exchange noted that investigators identified malicious activity tied directly to third-party security solutions, which included a previously unknown zero-day flaw. Furthermore, investigators successfully recovered a customized tool specifically deployed by the threat actor to initiate unauthorized withdrawals from the platform’s digital asset reserves.

The security crisis began unfolding publicly on September 24, 2026, when Bitget disclosed that malicious actors had siphoned $387.5 million from its hot and warm wallets through a coordinated series of unauthorized transfers. The staggering loss forced the exchange to immediately halt all user withdrawals as an emergency protective measure while internal and external security teams scrambled to contain the breach. In the immediate aftermath of the exploit, major industry players—including Circle, Tether, and NEAR Intents—stepped in to assist, successfully freezing close to $632,700 worth of cryptocurrency assets linked to the stolen funds before they could be fully laundered.

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Subsequent technical analyses released by Bitget revealed the mechanics behind the breach. The attackers reportedly exploited the third-party zero-day flaw to harvest high-level internal credentials. Armed with these privileged credentials, the threat actors were able to issue fraudulent withdrawal commands directly to the platform’s wallet system, executing abnormal transfers that cleverly bypassed existing automated risk controls and security safeguards. In response to the compromise, Bitget immediately notified the relevant third-party vendor and disabled the affected system functionalities pending a comprehensive security fix and audit.

The wide-ranging cyberattack impacted a total of 11 major blockchain networks, demonstrating a high degree of technical preparation and cross-platform capability by the perpetrators. The affected networks included Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. Among the substantial portfolio of stolen digital assets identified to date are XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, and TIA.

A comprehensive progress report published by SlowMist pushed the timeline of the attack back even further, revealing that the earliest malicious activity linked to the sophisticated campaign actually began weeks prior on August 31, 2026. According to SlowMist’s findings, a service running on one of the nodes belonging to an affected third-party product, designated as Product A, was compromised via the zero-day vulnerability. The attacker executed a hidden script within the service process, launched a command to read sensitive environment variables containing database passwords, and successfully connected to the underlying database.

Additional hidden-script activity was subsequently detected by security analysts on two other nodes belonging to the infrastructure on September 23 and September 25, 2026. These critical findings proved that the affected service environments had been covertly compromised and seeded with persistent access well before the actual unauthorized token transfers were executed.

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

The operation escalated significantly on September 25, 2026, when the threat actor leveraged the compromised identity of an internal employee to access the management platform of a second third-party offering, referred to as Product B. During this phase, the attacker made three consecutive attempts to inject system commands directly into the product’s task parameters with the intent of writing malicious files onto the server. SlowMist noted that the attacker subsequently submitted code through the platform’s web execution endpoint, attempting to modify server configurations, establish a communication relay file, and upload as well as assemble malicious program files in batches.

Another pivotal discovery in the SlowMist report involved the custom-built operational tool utilized by the threat actor to drain the exchange’s wallets. Security analysts recovered the program among a collection of deleted files. Highly tailored specifically to interact with the unique withdrawal logic of Bitget’s wallet architecture, the bespoke tool began running and actively executing cryptocurrency thefts at 01:49 a.m. on September 25, 2026.

Parallel forensic investigations conducted by Google-owned Mandiant corroborated these findings, concluding that the external attackers successfully gained unauthorized access to specific third-party security appliances, identified as Product A and Product B, before leveraging that initial foothold to move laterally into Bitget’s core wallet environment.

According to Mandiant’s technical update, the threat actor deployed a web shell onto security appliance B and established a persistent Command-and-Control connection. Utilizing this established persistence on appliance B, the attackers executed lateral movement directly into Bitget’s production wallet job server, where they proceeded to deploy malicious packages. Mandiant emphasized that the threat actors systematically compromised network and security appliances, weaponizing them to distribute malicious packages and ultimately secure absolute operational control over the internal wallet job server.

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

As investigations into the attribution of the heist progress, Bitget reported that on-chain analysis and observed IP behavior patterns strongly indicate the operation was carried out by sophisticated North Korean threat actors. This assessment has been further supported by blockchain intelligence firms Elliptic and TRM Labs, which uncovered notable wallet address overlaps linking the laundering patterns of the stolen funds to illicit proceeds harvested from previous high-profile cryptocurrency hacks.

Leave a Reply

Your email address will not be published. Required fields are marked *