2026 Bitget — $387.5M wallet theft via zero-days on third-party security appliances
Data compromised
Cryptocurrency from hot/warm wallets (~$387.5M across ETH, XRP, BNB, AVAX, USDT, USDC and other tokens on multiple chains); customer account PII census not published as the primary impact
Technical writeup
Bitget confirmed attackers stole approximately $387.5 million after exploiting zero-day flaws in two third-party security appliances (labeled Product A/B in public summaries). SlowMist and Mandiant investigations (published/quoted September 30, 2026) describe earliest malicious activity as early as August 31, web-shell persistence on appliance B, lateral movement to the production wallet job server, and a custom withdrawal tool used after midnight September 25. Transfers spanned multiple chains over roughly three hours. CEO Gracy Chen attributed the intrusion pattern to North Korean actors. Bitget suspended withdrawals, later resumed Bitcoin withdrawals, and launched a recovery bounty. recordsAffected 0 reflects no published customer-PII headcount; companyConfirmed true for the wallet compromise and forensic narrative.
Root cause
Zero-day exploitation of two third-party security appliances → web shell / malware on production wallet job server → unauthorized withdrawals
References
- https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
- https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/
- https://github.com/slowmist/Knowledge-Base/blob/master/open-report-V2/incident-response/SlowMist%20Investigation%20Progress%20Report%20-%20Bitget_en-us.pdf