// 1 CRITICAL · 2 ZERO-DAY · 3 CVE IN THE LAST 24H→
On September 24, 2026, cryptocurrency exchange Bitget lost approximately $387.5 million after attackers exploited a zero-day vulnerability in at least two third-party security appliances. Cold wallets and private keys remained untouched; the breach occurred through the security supply chain itself.

Cold wallets were intact. Private keys were never touched. Yet on September 24, 2026, cryptocurrency exchange Bitget lost roughly $387.5 million. The attackers reached the treasury without cracking the vault: they simply deceived the guards.

At 18:31 UTC on September 24, Bitget detected unauthorized transfers from its hot and warm wallets. The initial estimate was $351.6 million, later revised to approximately $387.5–388 million. The mechanism: a zero-day vulnerability in at least two third-party security products—identified in forensic reports as "Product A" and "Product B"—that allowed attackers to obtain high-level internal credentials and inject fraudulent withdrawal commands into the wallet backend.

Key Takeaways
  • Theft of approximately $387.5 million without compromise of private keys or cold wallets.
  • SlowMist traced the earliest malicious activity to August 31, 2026: a dwell time of roughly 25 days.
  • Mandiant confirmed compromise of both security appliances, with a web shell on Product B and a C2 channel.
  • Attribution to North Korean actors assessed as "very likely" by Bitget and Elliptic, but not definitively confirmed.

The Technical Mechanism: How to Steal Without Breaking a Private Key

According to investigations by SlowMist and Mandiant, reported by The Hacker News, the attack began with Product A. SlowMist documented: "A service running on one of Product A's nodes was affected by a zero-day vulnerability. The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database."

From this point, attackers obtained internal credentials sufficient to move as authorized operators. Mandiant described the next phase: "The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection. Using the persistent access on security appliance B, the threat actor moved laterally to Bitget's production wallet job server and deployed malicious packages."

Persistent access was masked as routine operations. As CEO Gracy Chen stated, quoted by U.Today via The Hacker News: "Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions."

A custom withdrawal tool, "Highly tailored to the wallet system's withdrawal logic," was recovered by investigators. According to Rescana, the tool executed at 01:49 on September 25, 2026. However, BleepingComputer and SlowMist indicate 02:31 UTC+8—corresponding to 18:31 UTC on September 24—as the time of the first detected transfer. The discrepancy may reflect the distinction between tool execution and first detected fund movement.

The malware injected withdrawal commands into the backend workflow, where they were treated as legitimate. No private keys were touched.

"Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker to initiate unauthorized withdrawals" — Bitget, quoted by The Hacker News

25 Days of Dwell Time: Reconnaissance and Preparation

SlowMist dated the earliest malicious activity to August 31, 2026. This dwell time of roughly 25 days allowed attackers to understand Bitget's withdrawal logic and develop a custom tool.

The impact spanned 12 hot/warm wallet addresses and 11 different blockchains: ETH, XRP, BNB, AVAX, USDT, USDC, ZEC, ATOM, ALGO, and TIA.

The North Korean Attribution: Likely, Not Proven

Bitget and Elliptic assessed attribution to North Korean actors as "very likely" and "highly likely." The Hack Academy noted, however, that this "does not establish North Korean responsibility as confirmed fact." TRM Labs confirmed it had not made "a firm attribution."

The technical sophistication—zero-day against security products, custom tooling, extended dwell time, masquerading as administrative operations—is consistent with high-level APT groups, but not exclusive to them.

What Changes

The incident exposes a structural blind spot: the security supply chain itself. Bitget was not compromised due to its own defects or direct operational negligence. It was struck through the very products commissioned to protect it.

The crypto industry shares this vulnerability with much of the technology sector, but with immediate and irreversible financial implications. The lesson is not merely technical: it is organizational. Trust placed in third-party tools cannot substitute for independent verification of critical approval paths.

The full Mandiant and SlowMist forensic report is not publicly available. The vendors behind Product A and Product B have not been disclosed. No CVE or vendor advisory has been published. These limits make it impossible to assess the vulnerability's scope beyond Bitget's perimeter.

Analysis: The Paradox of Protection Becoming Vulnerability

The Bitget case inverts the conventional narrative of crypto hacks. Key management did not fail, nor did cold custody. The trust in the pipeline connecting human decision to automated execution failed. Attackers understood that the path of least resistance did not run through cryptography, but through technical social engineering: legitimate credentials, legitimate behaviors, legitimate tools used for illicit purposes.

This pattern—long dwell time, masquerading as routine administration, development of tailored tools—demands a recalibration of controls. Not just key protection, but continuous monitoring of behavioral anomalies even from authorized accounts.

Bitget suspended withdrawals immediately and restored Bitcoin by September 27–28. Circle, Tether, and NEAR Intents froze approximately $1.1 million in assets. The Protection Fund, initially 5,500 BTC (over $464 million), was partially restored by October 2–4 with roughly $309 million. Full recovery remains uncertain.

September 2026 recorded a 462% increase in crypto hack losses compared to August, according to market data reported by Yahoo Finance. Bitget accounts for the largest share of this surge.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. thehackernews.com
  2. bleepingcomputer.com
  3. shattered.io
  4. rescana.com
  5. thehackacademy.com
  6. finance.yahoo.com