Full Report
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker
Analysis Summary
# Incident Report: Bitget Third-Party Zero-Day Exploitation
## Executive Summary
Bitget, a major cryptocurrency exchange, suffered a significant security breach resulting in the theft of approximately $387.5 million in digital assets. The attack was executed by North Korean threat actors who exploited a zero-day vulnerability in third-party security products to gain internal credentials and bypass risk controls. The exchange has since frozen a small fraction of the funds and disabled the compromised third-party functionalities.
## Incident Details
- **Discovery Date:** September 24, 2026
- **Incident Date:** August 31, 2026 – September 25, 2026
- **Affected Organization:** Bitget
- **Sector:** Financial Services (Cryptocurrency Exchange)
- **Geography:** Global / Singapore-based
## Timeline of Events
### Initial Access
- **Date/Time:** August 31, 2026
- **Vector:** Zero-day vulnerability in "Product A" (Third-party security product).
- **Details:** Attackers exploited a flaw in a service running on one of the product's nodes. They executed a hidden script to read environment variables, allowing them to steal database passwords and establish a connection to the backend database.
### Lateral Movement
- **Date/Time:** September 23 – September 25, 2026
- **Details:** After compromising "Product A," the threat actor pivoted to "Product B" (another management platform) using a compromised internal employee identity. They injected system commands into task parameters to write malicious files, modified server configurations, and deployed a web shell to establish Command-and-Control (C2).
### Data Exfiltration/Impact
- **Date/Time:** September 25, 2026 (Starting at 01:49 a.m.)
- **Details:** Using the lateral access gained, the attackers reached Bitget's production wallet job server. They deployed a customized, bespoke tool tailored to the wallet's withdrawal logic to bypass risk controls and initiate unauthorized transfers across 11 different blockchains.
### Detection & Response
- **Discovery:** Detected on September 24/25, 2026, following "abnormal transfers."
- **Response Actions:** Temporarily halted all withdrawals; engaged SlowMist and Mandiant for forensic investigation; coordinated with Circle, Tether, and NEAR Intents to freeze $632,700 in stolen assets.
## Attack Methodology
- **Initial Access:** Exploitation of a zero-day vulnerability in a third-party security appliance.
- **Persistence:** Deployment of web shells on security appliances and hidden scripts under service processes.
- **Privilege Escalation:** Use of stolen internal employee identities to access management platforms.
- **Defense Evasion:** Use of hidden scripts, batch-assembled malicious program files, and deletion of tools post-execution.
- **Credential Access:** Reading environment variables to obtain database passwords; theft of high-level internal credentials.
- **Discovery:** Reconnaissance of wallet withdrawal logic and server configurations.
- **Lateral Movement:** Pivoting from security appliance nodes to the production wallet job server.
- **Collection:** Identifying hot and warm wallet balances across multiple blockchains.
- **Exfiltration:** Unauthorized withdrawal commands issued via a bespoke automated tool.
- **Impact:** Financial theft of $387.5M and temporary operational shutdown of withdrawal services.
## Impact Assessment
- **Financial:** Estimated loss of $387.5 million; approximately $632,700 recovered/frozen.
- **Data Breach:** Compromise of internal database credentials and employee identities.
- **Operational:** Temporary suspension of all platform withdrawals; disruption of services across 11 blockchains.
- **Reputational:** Significant public impact due to the scale of the theft and association with North Korean threat actors.
## Indicators of Compromise
- **Network Indicators:** C2 connections established from security appliance B (specific IPs/domains not listed in text, but identified as [defanged] abnormal C2 traffic).
- **File Indicators:** Bespoke withdrawal tool (recovered from deleted files), malicious program files uploaded in batches, and communication relay files.
- **Behavioral Indicators:** Consecutive attempts to inject system commands into task parameters; "abnormal transfers" bypassing standard risk thresholds.
## Response Actions
- **Containment:** Disabled affected third-party product functionality; halted all platform withdrawals.
- **Eradication:** Recovered and analyzed deleted attacker tools; identified and blocked compromised internal accounts.
- **Recovery:** Collaborated with stablecoin issuers to freeze assets; working with third-party vendors on zero-day patches.
## Lessons Learned
- **Supply Chain Risk:** Security products themselves can become the primary vector for high-impact breaches if they possess zero-day flaws.
- **Credential Protection:** Environment variables containing sensitive database passwords provided a "path of least resistance" for the attackers.
- **Logic Tailoring:** Attackers are increasingly using highly customized tools designed specifically to interact with the target's unique internal withdrawal logic.
## Recommendations
- **Zero-Trust Architecture:** Implement stricter segmentation between security management appliances and production wallet job servers.
- **Secrets Management:** Avoid storing sensitive credentials like database passwords in environment variables; utilize dedicated secret management vaults with just-in-time access.
- **Enhanced Monitoring:** Implement behavioral analytics that trigger immediate alerts when administrative platforms (Product B) attempt to write files or modify server configurations.
- **Vendor Risk Management:** Conduct deeper security audits of third-party vendors who have high-level access to internal infrastructure.