thehackernews.com 1 Oct 2026, 05:21 UTC

Bitget Heist Traced to Zero-Day in Third-Party Security Product

CyberSIXT Evidence Panel Source marked as original reporting

BITGET has confirmed that the $387.5 million crypto heist in late September was enabled by a zero-day in a third‑party security product. Ongoing investigations led by SlowMist indicate the attackers exploited the flaw to obtain high‑level internal credentials and issue fraudulent withdrawal commands, triggering a chain of abnormal transfers that bypassed Bitget’s risk controls.

The firm disclosed the incident on 24 September 2026 and temporarily halted withdrawals; Circle, Tether, and NEAR Intents subsequently froze around $632,700 in assets.

SlowMist’ s progress report traces malicious activity back to 31 August 2026, with hidden scripts running on compromised nodes and a read of an environment variable containing the database password. The investigation also notes similar hidden-script activity on two other nodes on 23 and 25 September, suggesting the affected service environments were already compromised before assets were moved.

On 25 September, investigators say an attempt was made to access a different third‑party product’s management platform via an internal employee identity, deploying web‑execution payloads to alter server configuration and write malicious files. A bespoke tool, likely tailored to the wallet withdrawal logic, appeared in recovered files and began siphoning assets early on 25 September.

Mandiant’s assessment corroborates that attackers gained unauthorised access to certain third‑party security appliances and used that access to move laterally into Bitget’s wallet environment, deploying a web shell and a C2 channel. Bitget and third‑party threat intelligence groups, including Elliptic and TRM Labs, have linked the activity to North Korean actors.

The attack affected 11 blockchains and a wide range of assets, with ongoing work to determine the full scope of the compromise and appropriate remediation steps.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline