On September 24–25, 2026, Bitget confirmed the theft of $387.5 million in digital assets after attackers exploited a zero-day vulnerability in third-party security products, an incident independently investigated by SlowMist and Mandiant. The attackers obtained high-level internal credentials, issued fraudulent withdrawal commands that bypassed existing risk controls, and automated the theft across 11 blockchains.
Bitget breach timeline and technical details
The earliest detected malicious activity occurred on August 31, 2026, when a hidden script was observed on a node of a security product identified in reporting as Product A. Similar hidden-script activity appeared again on September 23 and September 25. On September 24, attackers gained unauthorized privileged access to two third-party security appliances (referred to as Product A and Product B), deployed a web shell on Product B and established a command-and-control channel.
Using the compromised appliances, the attackers extracted environment variables that contained database credentials, connected to internal databases, escalated privileges, and moved laterally to Bitget’s production wallet job server. They deployed malicious packages and executed a custom withdrawal tool at 01:49 a.m. on September 25, 2026. The automated theft ran for nearly three hours and impacted assets across 11 blockchains: Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia.
Scope, detection and immediate response
Bitget detected multiple unauthorized transfers from hot and warm wallets on September 24–25, 2026, halted all withdrawals and initiated incident response procedures. The attackers’ actions indicate familiarity with Bitget’s internal processes and security architecture, since they were able to bypass risk controls using stolen credentials and a tailored withdrawal tool. No public hashes or technical indicators for the custom tools or malware used have been disclosed as of the publication dates.
Attribution and investigative findings
Attribution was assessed as likely North Korean threat actors, based on IP behavior, on-chain analysis and wallet overlaps with previous attacks, as reported by Elliptic and TRM Labs. SlowMist and Mandiant mapped the campaign to multiple MITRE ATT&CK techniques, including T1190, T1059, T1552.001, T1505.003, T1021, T1570, T1078, T1567 and T1562.
Impact on assets and freezing actions
The theft involved a range of assets including ETH, XRP, BNB, AVAX, USDT, USDC, ZEC, ATOM, USD0, XAUt, TRX, ALGO and TIA. Circle, Tether and NEAR Intents froze a total of $1.1 million in assets following the incident. No public indicators of compromise (IOCs) were available at the time of reporting.
Mitigation recommendations
Security recommendations prioritized by severity in the investigation include:
– Critical: Immediately review deployment and configuration of all third-party security products with privileged access, include them in vulnerability management and incident response plans, and require vendors to provide timely security updates and clear vulnerability disclosure processes.
– High: Monitor security appliances and critical systems for unauthorized script execution, web shell deployment and abnormal network connections; implement layered, independent controls to avoid single points of failure.
– Medium: Assess the security posture of vendors providing security tools, including their history of vulnerability management and incident response, and confirm fallback procedures if a security product is compromised.
– Low: Regularly update incident response plans to cover compromises of security tooling and participate in sector-specific threat intelligence sharing.
Organizations are advised to monitor updates from Bitget, SlowMist, Mandiant and trusted threat intelligence sources and to validate any indicators before enforcement.

