Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On October 2, 2026, Bitget published the forensic reconstruction of the theft that drained its hot and warm wallets on September 24. Investigations by SlowMist and Mandiant point to a cause that inverts the usual logic of cyber defense: the compromise occurred through a zero-day vulnerability in third-party security products — tools meant to protect the infrastructure that instead became the entry point.
- Initial malicious activity is dated to August 31, 2026 — roughly three weeks before funds began moving on-chain on September 24.
- The attacker deployed a web shell with a C2 connection on security appliance B, moving laterally to Bitget's production wallet job server.
- SlowMist recovered a custom withdrawal tool from deleted files that forged withdrawal parameters compatible with the wallet system, without compromising private keys.
- On-chain exfiltration lasted approximately 2 hours and 52 minutes; roughly $1.1 million was frozen by stablecoin issuers and protocols.
The Compromise Chain: From Product A Node to Wallet Job Server
According to SlowMist, the first sign of malicious activity in available logs dates to August 31, 2026. A service running on one of the "Product A" nodes — the designation used in reports for the third-party security appliance whose vendor has not been identified — was hit by a zero-day vulnerability. The attacker executed a script hidden under the service process, issued a command to read the environment variable containing the database password, and connected to the database itself.
On September 24, 2026, as documented by Mandiant, the threat actor gained unauthorized privileged access to security appliances A and B. A web shell was deployed on appliance B and a Command-and-Control (C2) connection established. Leveraging persistent access, the attacker moved laterally to Bitget's production wallet job server, where malicious packages were installed.
The core of the operation lies in the withdrawal tool recovered by SlowMist from deleted files. The software is described as "highly customized" and built around the withdrawal logic of Bitget's wallet system. It forged withdrawal parameters without compromising private keys. Mandiant explicitly ruled out that Bitget's private keys were compromised and that cold wallets were involved.
"Forensic findings indicate that on September 24, 2026, a threat actor gained unauthorised privileged access to Bitget's third party security appliances A and B. The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection." — Mandiant, reported by BleepingComputer
The Time Window: 24 Days of Persistence, 2 Hours and 52 Minutes of Exfiltration
The duration of persistent access — roughly three weeks between initial entry and fund exfiltration — stands out as one of the most significant elements of the reconstruction. The attacker operated in stealth mode through security infrastructure that, by definition, holds elevated privileges and broad visibility into the internal network.
The on-chain phase was rapid and intensive. The first verified transfer occurred at 18:31 UTC on September 24: 93 TRX, followed 11 seconds later by 0.84 ETH. According to SlowMist, the entire exfiltration sequence lasted approximately 2 hours and 52 minutes, concluding at 21:23 UTC. In that window, the attacker distributed assets across 11 blockchains: Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia.
Attribution, Impact, and Frozen Funds
Bitget attributes the attack to North Korean threat actors based on IP behavior patterns and on-chain analysis. According to BleepingComputer's report, Elliptic and TRM Labs flagged overlaps with wallets used to launder proceeds from previous attacks. The attribution remains a working theory; no official government confirmation has emerged.
The financial impact was quantified at $387.5 million, revised from an initial estimate of $351.6 million after the addition of ZEC and TRON. Approximately $1.1 million in assets was frozen by Circle, Tether, and NEAR Intents. Bitget's User Protection Fund, holding over $464 million at the time of the incident, covers the loss. Bitget has offered a 5% bounty for the recovery or freezing of stolen funds.
Analysis: The Paradox of Security as Attack Surface
The Bitget incident raises structural questions about security governance. Third-party security appliances operate with elevated privileges, often with access to critical network segments. When these tools become compromise vectors, the defense perimeter transforms into attack surface.
The customized withdrawal tool — built around the wallet system's logic — indicates a pre-attack reconnaissance phase. The source does not specify how the attacker obtained or forged the internal employee's identity. The vendor identity for "Product A" and "Product B" has not been disclosed; no CVEs have been assigned, no official advisories or patch confirmations have emerged.
What Remains Unknown
The incident leaves open questions that reflect the current limits of the dossier:
- The vendor of the third-party security products has not been identified; no CVE or official advisory exists for the zero-day.
- The exact duration of persistent access between August 31 and September 24 is unknown, as is how the attacker maintained persistence.
- Attribution to North Korean threat actors is not confirmed by official government sources.
- The precise percentage of funds frozen, recovered, or still moving beyond reported data is not confirmed.
This reconstruction relies primarily on CryptoTimes' report, which converted the UTC timeline; SlowMist and Mandiant citations are relayed through editorial outlets rather than primary vendor communications.
Editor's Note
The Bitget case documents a recurring pattern in the sector: the compromise of defense tools as a primary access vector. Twenty-four days of persistence through security appliances, followed by on-chain exfiltration in under three hours, highlights an imbalance between attacker preparation time and victim response time. Whether this pattern is systemic or confined to Bitget's specific architecture cannot be determined from available material.
Information verified against cited sources and current as of publication.
Sources
- https://www.cryptotimes.io/2026/09/30/bitget-387-5m-hack-slowmist-and-mandiant-say-zero-day-attack-began-weeks-before-theft/
- https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
- https://www.hendryadrian.com/bitget-confirms-third-party-zero-day-behind-387-5-million-cryptocurrency-theft/
- https://thehackernews.com/2026/10/bitget-confirms-third-party-zero-day.html
- https://forkast.news/the-bitget-breach-when-security-layers-become-attack-surfaces/
- https://www.bleepingcomputer.com/
- https://www.bleepingcomputer.com/tutorials/
- https://www.bleepingcomputer.com/download/
- https://deals.bleepingcomputer.com/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.