Full Report
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most
Analysis Summary
# Incident Report: Bitget Third-Party Security Product Compromise
## Executive Summary
Bitget, a major cryptocurrency exchange, suffered a security breach resulting in the theft of approximately $388 million in digital assets. The attacker exploited a zero-day vulnerability in a third-party security product to obtain high-level internal credentials, subsequently triggering fraudulent withdrawals from hot and warm wallets. The exchange has restored operations and committed to covering all customer losses via its Protection Fund.
## Incident Details
- **Discovery Date:** September 24, 2026
- **Incident Date:** September 24, 2026
- **Affected Organization:** Bitget
- **Sector:** Financial Services / Cryptocurrency Exchange
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** Preceding September 24, 2026
- **Vector:** Exploitation of a third-party security product vulnerability.
- **Details:** The attacker exploited a zero-day flaw in an unnamed security tool used by the exchange to harvest high-level internal management credentials.
### Lateral Movement
- Using stolen credentials, the attacker gained access to Bitget's internal management system and wallet-related backend services.
### Data Exfiltration/Impact
- **Date/Time:** September 24, 2026, 18:31 UTC
- **Details:** The attacker executed two small test transfers to probe risk-control thresholds. Approximately 30 minutes later, the attacker initiated large-scale fraudulent withdrawal commands, successfully stealing $388 million.
### Detection & Response
- **Discovery:** System anomalies were identified following the bypass of risk controls.
- **Response actions:** Bitget isolated affected systems, revoked/reissued credentials, and suspended withdrawal services. External firms Mandiant and SlowMist were engaged for the forensic investigation.
## Attack Methodology
- **Initial Access:** Exploitation of a zero-day vulnerability in a third-party security vendor's product.
- **Persistence:** Not explicitly detailed, but involved maintaining access to internal management systems.
- **Privilege Escalation:** Exploited the third-party flaw to obtain "high-level internal credentials."
- **Defense Evasion:** Activity was disguised as routine administrative operations; traces of actions were removed; test transfers were used to stay below risk-control thresholds.
- **Credential Access:** Stolen through the vulnerability in the security product.
- **Discovery:** Reconnaissance of internal risk-control thresholds.
- **Lateral Movement:** Accessing wallet backend services from the internal management system.
- **Collection:** Spoofing transaction data within the backend to trigger approval processes.
- **Exfiltration:** Fraudulent withdrawal commands to external wallets.
- **Impact:** Financial theft of $388M from hot and warm wallets.
## Impact Assessment
- **Financial:** Loss of ~$388 million (to be covered by Bitget’s Protection Fund).
- **Data Breach:** Fraudulent transaction data; high-level administrative credentials compromised.
- **Operational:** Temporary suspension of all withdrawals; staged resumption of services through October 2.
- **Reputational:** High public visibility; potential links to North Korean state-sponsored actors (TraderTraitor).
## Indicators of Compromise
- **Network indicators:**
- 0x770b10b273fc44fe9197d6bf20f145c2e98463ee (Ethereum/EVM)
- rwNhefsz1UQEusxhCvHip3[truncated] (XRP)
- **File indicators:** None disclosed in initial report.
- **Behavioral indicators:** Test transfers just below alert thresholds followed by rapid large-scale withdrawals; administrative actions occurring without corresponding authorized tickets.
## Response Actions
- **Containment:** Isolated affected systems and turned off compromised functionality.
- **Eradication:** Revoked and reissued all internal credentials.
- **Recovery:** Restored Bitcoin withdrawals on September 28; phased restoration for other assets; activated Protection Fund to ensure zero impact on customer balances.
## Lessons Learned
- **Key takeaways:** Third-party security tools can become a single point of failure if they possess high-level permissions.
- **What could have been done better:** Stricter "blind" validation for large withdrawals that does not rely solely on internal administrative credentials.
## Recommendations
- **Vendor Risk Management:** Conduct more rigorous security audits and zero-day assessments of third-party security vendors.
- **Multi-Party Computation (MPC):** Ensure withdrawal approvals require independent, multi-factor validation that cannot be bypassed by a single compromised management system.
- **Enhanced Monitoring:** Implement behavioral analytics to detect "low and slow" testing patterns that precede large-scale exfiltration.