Bitget loses $387.5 million as attackers exploit zero-days in third-party security tools
Attackers drained $387.5 million from Bitget's hot wallets on September 24 by abusing zero-days in third-party security appliances. The exchange suspects North Korean hackers.
At a glance
- Bitget detected unauthorized hot wallet transfers at 18:31 UTC on September 24; the loss estimate rose from $183 million to $387.5 million.
- Forensics cited by BleepingComputer and The Hacker News trace initial access to August 31 via a zero-day in an unnamed third-party security product.
- Attackers used a custom tool to spoof transaction data and push fraudulent withdrawals past risk controls; Bitget says private keys were not stolen.
- CEO Gracy Chen points to North Korean actors, and Elliptic and TRM Labs reportedly found wallet overlaps with earlier North Korea-linked hacks.
Cryptocurrency exchange Bitget lost $387.5 million after attackers exploited zero-day vulnerabilities in third-party security products, gained a foothold in its wallet infrastructure and pushed fraudulent withdrawals from its hot wallets on September 24, 2026. According to BleepingComputer and The Hacker News, the company has linked the intrusion to North Korean threat actors, making it one of the largest exchange thefts of the year and a stark example of security appliances themselves becoming the entry point.
What happened
According to Decrypt, Bitget's security systems detected unauthorized transfers from hot wallets at 18:31 UTC on September 24. On-chain investigators initially tallied about $183 million in losses within roughly an hour; the figure was later updated to $351.6 million and then, on September 25, to $387.5 million by CEO Gracy Chen. BleepingComputer reported that the theft took place between 02:31 and 05:23 UTC+8 on September 25, local time.
The stolen funds included ETH, XRP, BNB, AVAX, USDT, USDC and other tokens. The Hacker News said the incident spanned 11 blockchains, while Decrypt reported that about 103 million XRP, worth roughly $157 million, made up the largest single portion. Bitget suspended withdrawals after spotting the transfers and launched a recovery bounty program offering 5% of recovered funds, BleepingComputer said. The Hacker News reported that Circle, Tether and NEAR Intents had frozen about $1.1 million of the stolen assets.
Technical details
Forensic findings from SlowMist, cited by both outlets, place the earliest malicious activity on August 31, when attackers exploited a zero-day in an unnamed third-party security product ("Product A"), ran a hidden script under its service process and read database credentials from environment variables. The Hacker News said similar compromises hit two more nodes between September 23 and 25, and attackers used stolen employee credentials to access the management platform of a second product.
The intruders then deployed a web shell on a security appliance, set up command-and-control connections and distributed malicious packages to the wallet job server. Mandiant concluded that the threat actor compromised network and security appliances and used them to gain control over that server, according to The Hacker News. A bespoke tool tailored to Bitget's withdrawal logic let the attackers spoof transaction data so that fraudulent payouts passed risk checks. Chen told Decrypt the attackers neither forged user withdrawal requests nor obtained private keys. Bitget said it notified the vendor and disabled the affected functionality.
Who is affected
Chen attributed the attack to North Korean hackers based on IP behavior and on-chain patterns, though Decrypt noted she initially stressed the attacker's identity was unconfirmed. The Hacker News reported that Elliptic and TRM Labs found overlaps with wallets used to launder proceeds from earlier North Korea-linked hacks. Decrypt said Bitget's user protection fund held about $464 million at the time of the incident, more than the reported loss.
What to do
Organizations, especially those handling digital assets, should treat security and network appliances as high-value targets: restrict and monitor their management interfaces, watch for unexpected scripts and web shells on them, and avoid storing database credentials in plain environment variables. Withdrawal pipelines should validate transactions independently of upstream systems that could be spoofed.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



