← Blog

Bitget Hack: $387.5M Stolen via Zero-Day Security Appliances

Share on X

Bitget said attackers walked away with roughly $387.5 million in cryptocurrency after breaking in through zero-day flaws in two third-party security appliances, then pivoting into the exchange’s wallet operations. The company disclosed the theft on September 25, 2026, suspended withdrawals, and later published findings from blockchain firm SlowMist and Google Cloud’s Mandiant. This is a verified custody incident — exchange hot and warm wallets drained across multiple chains — not a published census of customer names, emails, or government IDs. If you are searching whether the Bitget data breach exposed your KYC file, the public record so far points to treasury loss and operational fraud, not a mass personal-data dump.

That distinction matters for anyone asking was I affected. Users who kept balances on Bitget at the time of the unauthorized transfers may see account-level impacts, frozen withdrawals, or delayed crediting while the exchange stabilizes reserves. Users who only held assets elsewhere are not in a “your SSN leaked” story — unless scammers contact you anyway, which they will. The Bitget hack 2026 narrative is already spawning fake recovery pages and “refund” bots. Treat those as hostile until Bitget confirms them on its official domains.

The canonical incident record on BreachHistory is here: /bitget/bitget-wallet2026 (https://breachhistory.com/bitget/bitget-wallet2026).

What happened — timeline

Reporting from BleepingComputer on the initial heist described unauthorized transfers from Bitget’s hot and warm wallets and a suspension of all withdrawals once the exchange detected the activity. A follow-up on September 30, 2026 tied the theft to a longer intrusion: zero-days in vendor security gear, lateral movement, and a bespoke tool used to pull funds after midnight on September 25.

SlowMist’s investigation progress report (hosted on GitHub) places the earliest malicious activity in available logs around August 31. On one node of “Product A,” a service was hit by a zero-day. The attacker ran a hidden script under the service process, read an environment variable holding a database password, and connected to the database. Similar hidden-script activity showed up on two other Product A nodes on September 23 and September 25.

Mandiant’s summary, cited in Bitget’s status materials and quoted by BleepingComputer, focuses on September 24: privileged access to third-party security appliances A and B, a web shell on appliance B, command-and-control, then lateral movement to Bitget’s production wallet job server and deployment of malicious packages. After that pivot, investigators describe malware on the wallet server and a custom withdrawal tool used to execute the theft starting after midnight on September 25.

SlowMist tracked on-chain movement: the first stolen transfer in that window landed at 02:31 (UTC+8) on September 25, the last at 05:23, spanning nearly three hours and touching multiple blockchains. Bitget CEO Gracy Chen said the incident hit ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base — a who’s-who of assets a global crypto exchange would hold in operational wallets.

Withdrawals went dark immediately after detection. Bitget later resumed Bitcoin withdrawals while broader recovery work continued. The exchange also opened a Recovery Bounty Program offering up to 5% for help freezing or returning stolen funds.

What was exposed — and what this is not

In BreachHistory’s catalog, this row carries recordsAffected: 0 because no regulator or Bitget notice has published a count of customers whose personal identifiable information was exfiltrated. Do not read zero as “nobody was hurt.” It means the attested harm is measured in stolen crypto custody, not in a leaked username/password database or KYC archive with a published headcount.

What attackers targeted, per SlowMist and Mandiant:

  • Operational wallet infrastructure — hot and warm wallets used to process user balances
  • Backend systems that participate in withdrawal authorization
  • Third-party security appliances sitting on the path between “monitoring” and production

Chen told users the adversary also compromised a critical backend component used to spoof transaction data, which in turn tricked Bitget’s authorization flow into releasing funds from compromised wallets. That is an integrity attack on the exchange’s own signing pipeline, not a textbook “we left an S3 bucket open” leak.

What this is not, based on public disclosures to date:

  • A confirmed mass dump of customer legal names, home addresses, and passport scans with a published victim count
  • A cold-wallet breach of the kind that hit Bybit’s ETH cold storage in earlier North Korea–linked heists (Chen drew parallels to DPRK campaigns, but Bitget’s described loss centers on hot/warm operational wallets)
  • An unverified forum claim — Bitget, SlowMist, and Mandiant are on the record

If Bitget later notifies a defined set of users that KYC or support tickets leaked, update your personal risk model. Until then, prioritize wallet safety and scam resistance over credit-freeze workflows tied to imaginary “Bitget SSN leaks.”

How the attack worked — zero-day, web shell, custom withdrawer

The through-line in both forensic reports is uncomfortable for any fintech CISO: security products meant to reduce risk became the bridge.

Stage 1 — appliance zero-days (Product A)

SlowMist describes Product A nodes compromised via a zero-day against a service process. Hidden scripts harvested credentials from environment variables — classic post-exploitation tradecraft when DevOps stores secrets on-box. The August 31 timestamp means dwell time measured in weeks, not hours. That is long enough to map databases, learn job schedules, and wait for a wallet batch window.

Stage 2 — appliances A and B, web shell, C2 (September 24)

Mandiant’s language is blunt: unauthorized privileged access to both appliances, a web shell on B, and C2 connectivity. Web shells on security gear are particularly nasty; defenders often trust traffic originating from “the scanner” or “the SOC appliance.” Once an actor owns that host, lateral movement can masquerade as routine admin activity.

Stage 3 — wallet job server and malicious packages

From appliance B, the attacker reached Bitget’s production wallet job server — the kind of system that automates deposits, reconciliations, and withdrawal batches at scale. Packing malicious code into that environment is how you turn a monitoring compromise into treasury access. Mandiant notes malicious packages deployed there; SlowMist adds malware plus a custom withdrawal tool tuned to Bitget’s internals.

Stage 4 — authorization spoofing and multi-chain drains

Chen’s public thread emphasized spoofed transaction data feeding Bitget’s authorization process. Readers should picture broken trust boundaries: if the signing workflow believes a withdrawal request is legitimate because upstream telemetry lied, automated gates may release funds faster than humans can react — especially in a three-hour blast across many chains.

BleepingComputer noted Bitget had not yet named the third-party vendors or CVE identifiers when reporters asked on September 30. That gap is normal early in zero-day response; it also means other Bitget customers cannot yet patch a specific SKU. Watch for vendor advisories and CISA-style alerts in the coming days.

Who is at risk

Bitget users with on-exchange balances during the theft window. If your coins were held in Bitget custody (spot, earn products, or similar) while unauthorized transfers fired, you may face delayed withdrawals, internal make-good programs, or socialized loss mechanisms depending on how Bitget allocates the shortfall. Read official status posts; ignore Telegram “compensation forms.”

Users who withdrew before the incident. On-chain self-custody unaffected by Bitget’s hot-wallet loss still leaves you exposed to phishing that cites the headline dollar figure. Attackers blast “you are eligible for 5% bounty” emails to millions of addresses, not just victims.

DeFi and OTC counterparties. Stolen ETH, stablecoins, and altcoins will be laundered through mixers, bridges, and nested exchanges. Compliance teams should refresh blockchain tracing alerts for inflows tied to tagged Bitget-heist clusters once SlowMist or law enforcement publishes indicators.

Other exchanges and wallet platforms. The same appliance classes often appear in multiple enterprises. A zero-day in a widely deployed security product is a sector problem, not a Bitget-only footnote — similar to how appliance flaws have preceded breaches in other industries catalogued on BreachHistory, from vendor source-code exposure to cloud credential chains.

Retail investors hearing “North Korea.” Chen attributed the attack to patterns consistent with DPRK-linked groups, citing IP behavior and on-chain analysis. That is attribution from the CEO, not a FBI press release naming Lazarus for this specific event. Treat it as strong contextual framing — North Korean actors have dominated large crypto exchange heists — while separating political attribution from the mechanical facts Mandiant and SlowMist documented.

Campaign and industry context

State-linked thieves did not invent the idea of hitting operational wallets. They refined it. The FBI previously confirmed Lazarus behind the record-scale Bybit heist, where attackers stole about $1.5 billion from an ETH cold wallet — a different architecture than Bitget’s hot/warm focus, but the same downstream laundering playbook.

Bitget’s path — compromise security infrastructure, persist for weeks, automate withdrawals — rhymes with other 2026 incidents where trust anchors failed upstream of the crown jewels. Supply-chain and vendor-trust themes show up repeatedly in BreachHistory’s long-form coverage, including third-party tooling pivots in software security vendors and cloud credential chains at telecom BPO shops. The asset class changes; the lesson repeats: the vendor box on your VLAN is part of your attack surface.

For exchange operators, the incident is a stress test on segregation between monitoring appliances and signing systems, on secret management (environment variables readable from compromised services), and on withdrawal authorization that cannot be fooled by forged upstream state. For users, it is another reminder that “not your keys, not your coins” is not a meme — it is a risk allocation choice every time you leave size on an exchange.

What Bitget and investigators said

Bitget’s social channels and support articles acknowledged the theft, pointed to SlowMist and Mandiant, outlined withdrawal suspensions and partial resumption, and advertised the recovery bounty. Chen’s statements on X summarized affected assets and chains and argued DPRK-style tradecraft.

SlowMist published a PDF progress report suitable for technical readers — timelines, Product A scripting, transfer timestamps in UTC+8, and blockchain tracing notes. Mandiant’s contribution, embedded in Bitget’s PDF status update, supplies the appliance B web shell narrative and wallet-server package deployment.

BleepingComputer’s September 30 piece consolidates those sources and links the earlier dollar figure reporting. Taken together, they form the verified fact base for this blog: dollar amount (~$387.5M), access vector (zero-days in two third-party security products), dwell time (from ~August 31), execution window (post-midnight September 25, ~3 hours on-chain), forensic vendors (SlowMist, Mandiant), and operational response (withdrawal pause, BTC withdrawals back, bounty program).

What remains publicly unknown: exact vendor names, CVE numbers, whether user PII stores were touched, and how much crypto Bitget will recover through law enforcement or on-chain freezes. Spokespersons did not immediately answer BleepingComputer’s product-identification questions on publication day.

Was I affected? — practical checks

Start with source of truth: log in only via bitget.com (type it yourself; do not use ads or DMs). Read in-app announcements and the official support article on the Recovery Bounty Program. If Bitget emails you, verify headers and links before clicking — but remember legitimate mail can also arrive during crises, which is why phishers love crises.

Check your account history for unexpected withdrawals, failed login alerts, or new API keys you did not create. If you only used Bitget for spot trading, compare your last known balance screenshots or tax exports against current statements once the exchange republishes stable accounting.

On-chain, your personal self-custody wallets are unaffected unless you signed a malicious transaction yourself. Exchange custody is collective: the hot wallet is a shared pool. Bitget’s solvency and reimbursement policy determine individual outcomes more than a traditional “your row in the CSV leaked” breach.

Have I Been Pwned and similar services may not light up for this incident if no email database drops. That absence does not mean you should ignore phishing recovery scams — the scammers do not need a leak list to know you read crypto Twitter.

Phishing and fake recovery scams to expect

Every major hot wallet theft breeds the same parasite ecosystem:

  • Sites mimicking Bitget’s bounty form, asking for seed phrases to “verify ownership” of stolen funds
  • Telegram admins claiming they can merge your wallet into the 5% recovery pool if you send a “processing fee”
  • Emails citing the exact $387.5M figure and urging you to connect MetaMask to a “reimbursement dApp”
  • Fake Mandiant or SlowMist PDFs with macros, riding on the credibility of the real reports linked above
  • Support impersonators on X offering to “escalate” your case if you disable 2FA “temporarily”

Bitget’s real bounty program pays helpers who assist recovery — it does not ask users to export private keys. No legitimate investigator will remote into your laptop. Delete, block, and report.

If you already clicked a fake bounty link, revoke token approvals on chains you use, move remaining assets to fresh wallets, and assume any seed entered online is burned.

What you should do — numbered action list

  1. Use official channels only. Navigate to Bitget support articles and status updates from the primary domain. Bookmark them after typing the URL.
  2. Freeze new trust in DMs. Treat every unsolicited “Bitget refund” message as fraud until proven otherwise — including ones that know your email from unrelated leaks.
  3. Review exchange exposure. If you keep long-term holdings on any centralized exchange, decide whether this event triggers a move to hardware or multisig custody. Risk tolerance varies; the trade-off is operational convenience versus counterparty loss.
  4. Enable and harden 2FA. Use an authenticator app or hardware key for Bitget and any exchange where you still hold funds. SMS alone is weak, especially when support impersonators social-engineer SIM swaps.
  5. Rotate API keys. Traders with Bitget API access should delete unused keys, restrict IP allowlists, and disable withdrawal permissions on keys that only need read or trade scope.
  6. Monitor on-chain announcements. Follow SlowMist, Bitget, and major chain analytics firms for tagged addresses. Report suspicious inflows if you operate a business wallet.
  7. Document balances for taxes and claims. Export trade history now; crises get messy later. Screenshots with timestamps help if reimbursement programs appear.
  8. Do not pay “recovery fees.” Anyone demanding upfront crypto to release Bitget “locked” funds is scamming you.
  9. Watch for vendor patches. If you operate enterprise security appliances, subscribe to vendor advisories — the unnamed products in this incident may soon have CVEs that affect your stack too.
  10. Separate news from attribution. North Korea links are part of Chen’s public analysis; your personal action plan still starts with account hygiene and scam avoidance regardless of who stole the coins.

Technical lessons for defenders

Several details in SlowMist’s report deserve scrutiny inside security teams, even if you do not run an exchange.

Environment variables holding database passwords on appliance nodes are a single script away from total database compromise. Vault products, short-lived credentials, and network segmentation between monitoring tiers and production wallet VLANs are not luxury items after a nine-figure loss.

Hidden scripts running under service accounts on security appliances suggest defenders lacked integrity monitoring tuned for those hosts. If your EDR excludes the “security scanner” because performance, reconsider.

Custom withdrawal tooling implies the attacker studied Bitget’s job server semantics — likely through weeks of recon after the August foothold. Dwell time is the enemy of containment.

Authorization that trusts upstream transaction state without independent reconciliation is fragile. Dual-control signing, anomaly detection on batch sizes, and chain-specific velocity limits are mitigations exchanges advertise; incidents like this test whether those controls were live or bypassed by spoofed telemetry.

Zero-days in security products are a supply-chain class of their own. They echo other 2026 BreachHistory coverage where trusted vendor infrastructure became the entry point — worth comparing mentally to source-code repository intrusions and cloud control-plane credential theft, even though the exfiltration target here was on-chain assets rather than Git trees or petabyte file shares.

Withdrawals, solvency, and the bounty program

Pausing all withdrawals is the correct emergency brake when hot wallets bleed. Selectively restoring BTC while other assets remain under review is a communication tightrope: it signals partial normalization but does not guarantee all chains are equally safe yet.

The 5% Recovery Bounty Program aligns incentives for whitehats, OTC desks, and other exchanges to freeze tainted deposits when they see them. It does not replace law enforcement mutual legal assistance or on-chain bridge governance fights, but it can claw back meaningful percentages on fast-moving thefts.

Users should not interpret bounty marketing as a promise that every customer will be made whole overnight. Exchanges facing nine-figure holes historically combine insurance, treasury reserves, investor support, and token repayment plans — each with different legal implications depending on jurisdiction. Wait for audited statements rather than rumor threads.

Regulatory and legal outlook

Unlike healthcare or telecom breaches, this incident may not trigger a neat “X million residents notified” headline in U.S. state AG portals if no personal data census accompanies the wallet theft. Regulatory interest can still arrive via financial supervisors, anti-money-laundering agencies, and jurisdictions where Bitget holds licenses.

Class-action chatter often follows exchange losses. Evidence preservation — exports, communications, on-chain records — helps whether you pursue claims or simply need accurate tax treatment of any reimbursement tokens.

Customers in regions with strong consumer finance protections should watch whether Bitget frames make-goods as voluntary credits versus contractual obligations. That framing affects timelines and recourse.

Comparing hot wallet theft to classic data breaches

Traditional Bitget data breach searches sometimes assume email and password lists. This event’s verified scope is treasury and infrastructure integrity. Impact radiates through market confidence, withdrawal queues, and phishing surface — not through credit bureau monitoring for every account holder.

That said, exchanges hold KYC data internally. A separate intrusion path could still expose it; Mandiant and SlowMist have not publicly asserted a bulk PII exfiltration phase. BreachHistory will reflect published customer notices if they appear. Until then, calibrate expectations: your crypto counterparty risk spiked; your Equifax freeze is optional, not mandatory, based on current filings.

Contrast with incidents like retail order-tracking flaws or municipal ransomware leaks where named fields and victim counts dominate notices. Bitget’s public numbers are dollar-denominated and chain-denominated. Cataloguing recordsAffected as zero is honest given disclosures, not an attempt to minimize user harm.

Open questions to watch

Security researchers and customers should track several threads over the next weeks:

  • Vendor identification and patch availability for the compromised appliances
  • Independent confirmation or refinement of DPRK attribution beyond CEO statements
  • On-chain clustering updates from SlowMist and partner exchanges
  • Whether any affiliate leaked user emails or support tickets — would change personal risk calculus immediately
  • Full restoration timeline for withdrawals on each chain beyond BTC
  • Financial disclosures quantifying insurance coverage and corporate backstop

Each answer shrinks uncertainty for both retail users and competing exchanges re-auditing their own appliance deployments.

Canonical record and sources

BreachHistory incident page: https://breachhistory.com/bitget/bitget-wallet2026

Primary and authoritative reporting used in this article:

For related reading on vendor-trust failures and fintech incident response in 2026, see BreachHistory’s fixed related posts on Trellix source-code access, Checkmarx’s GitHub archive leak, Telus Digital’s cloud credential chain claim, Chime’s outage and litigation cycle, and Abrigo’s CRM-targeted extortion — each linked from this article’s metadata rather than duplicated here.

The Bitget hack 2026 will stay in headlines because of the dollar sign. The operational story — zero-days in the security stack you bought to sleep better, weeks of quiet footholds, a forged authorization path into hot wallet pools — is what defenders should carry into their next architecture review. Users should carry a simpler lesson: verify every recovery offer, assume exchange custody is a loan to someone else’s keys, and let official investigations, not Telegram speedruns, tell you whether your balance is whole again.