Full Report
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]
Analysis Summary
# Incident Report: Bitget $387.5M Cryptocurrency Theft
## Executive Summary
Between late August and late September 2026, Bitget cryptocurrency exchange was targeted in a sophisticated cyberattack resulting in the theft of $387.5 million in digital assets. The breach was facilitated by the exploitation of zero-day vulnerabilities in third-party security appliances, allowing attackers to move laterally into the production wallet environment. Bitget has attributed the activity to North Korean threat actors and is currently working with Mandiant and SlowMist to recover funds.
## Incident Details
- **Discovery Date:** September 25, 2026
- **Incident Date:** August 31, 2026 (Initial Access) – September 25, 2026 (Exfiltration)
- **Affected Organization:** Bitget
- **Sector:** Financial Services / Cryptocurrency Exchange
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** August 31, 2026
- **Vector:** Exploitation of zero-day vulnerability in third-party security appliances.
- **Details:** Attackers exploited a flaw in "Product A," running a hidden script to read environment variables and extract database credentials.
### Lateral Movement
- **September 23–24, 2026:** Attackers compromised a second security appliance ("Product B") and established persistence via a web shell and Command-and-Control (C2) connection.
- **September 24, 2026:** Using access from Product B, the threat actor moved laterally to Bitget’s production wallet job server.
### Data Exfiltration/Impact
- **September 25, 2026 (02:31 – 05:23):** Attackers deployed a custom withdrawal tool and malicious packages to the job server. They spoofed transaction data to bypass authorization, draining $387.5 million across multiple blockchains (ETH, XRP, BNB, etc.).
### Detection & Response
- **September 25, 2026:** Bitget detected unauthorized transfers and immediately suspended all withdrawals.
- **Post-Incident:** External forensics (Mandiant/SlowMist) were engaged to analyze logs and identify the zero-day entry points.
## Attack Methodology
- **Initial Access:** Zero-day exploitation of third-party security products.
- **Persistence:** Deployment of web shells on security appliances and C2 establishment.
- **Privilege Escalation:** Unauthorized privileged access obtained via security appliance exploitation.
- **Defense Evasion:** Use of hidden scripts running under legitimate service processes.
- **Credential Access:** Reading environment variables to steal database passwords.
- **Discovery:** Reconnaissance of the wallet infrastructure and database environments.
- **Lateral Movement:** Pivoting from security appliances to the production wallet job server.
- **Collection:** Spoofing transaction data to trigger legitimate fund movement processes.
- **Exfiltration:** Transfer of funds across Ethereum, Arbitrum, Avalanche, Optimism, BSC, and Base chains.
- **Impact:** Financial theft of $387.5 million.
## Impact Assessment
- **Financial:** $387.5 million USD in various cryptocurrencies stolen.
- **Data Breach:** Compromise of database credentials and backend system configurations.
- **Operational:** Total suspension of exchange withdrawals; disruption of production wallet services.
- **Reputational:** Significant public scrutiny regarding the reliance on vulnerable third-party security vendors.
## Indicators of Compromise
- **Network indicators:** C2 connections established from security appliance B [Defanged IP/URL data not provided in article, but referenced as North Korean patterns].
- **File indicators:** Malicious packages on production wallet job servers; custom withdrawal tool; web shells on appliances.
- **Behavioral indicators:** Hidden scripts running under service processes; unauthorized reading of environment variables.
## Response Actions
- **Containment:** Immediate suspension of all withdrawal operations.
- **Eradication:** Identification and patching of the zero-day vulnerability (coordinated with vendors); removal of web shells and malicious packages.
- **Recovery:** Launch of a "Recovery Bounty Program" (5% reward for fund recovery) and collaboration with law enforcement and blockchain security firms to freeze assets.
## Lessons Learned
- **Third-Party Risk:** High-security appliances can become the weakest link if they harbor zero-day vulnerabilities.
- **Detection Gap:** The attackers were inside the network for nearly a month (Aug 31 - Sept 25) before the final exfiltration triggered alarms.
- **Defense in Depth:** Internal systems (wallet servers) were accessible once the perimeter security appliance was breached, suggesting a need for tighter internal segmentation.
## Recommendations
- **Zero-Trust Architecture:** Implement stricter micro-segmentation between security management appliances and production wallet infrastructure.
- **Enhanced Monitoring:** Deploy behavior-based monitoring to detect unusual script execution under legitimate system service processes.
- **Secrets Management:** Avoid storing sensitive database credentials in environment variables; utilize dedicated, encrypted secrets management hardware (HSMs).
- **Vendor Auditing:** Perform rigorous third-party risk assessments and penetration testing on all security appliances deployed in critical paths.