Cryptocurrency exchange Bitget has confirmed that a recently discovered zero-day vulnerability in third-party security products underpinned last week’s massive $387.5 million hot and warm wallet robbery. The company’s findings, drawn from internal and forensic review by SlowMist, reveal a sophisticated intrusion that bypassed its risk controls and enabled large, unauthorized transfers.
What Bitget Found
The attack, detected on September 24, involved unauthorized withdrawals from Bitget’s hot and warm wallets across multiple blockchains. Bitget alleges the threat actor first exploited a zero-day flaw in a third-party security appliance, thereby gaining high-level internal credentials. These were used to issue fraudulent withdrawal commands that the platform’s safeguards failed to intercept. In response, Bitget disabled the impacted functionality and alerted the vendor while continuing its probe.
The breach touched eleven blockchains, including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. Assets stolen include more than just common tokens like ETH, USDT, USDC and XRP — they extend to more exotic holdings such as ATOM, ZEC, and TIA.
How It Unfolded
Forensics by SlowMist show that the intrusion began as early as August 31. The attackers embedded hidden scripts in a service hosted on one of the third party’s nodes, enabling them to harvest sensitive environment variables, such as database passwords, and ultimately connect to internal databases.
On September 23 and 25, compromised nodes showed additional script deployments — indicators that internal systems were under active control well before the bulk of the theft. On September 25, the attackers also reportedly gained access to another third-party product’s management interface using an internal employee’s identity. There, they injected system commands, wrote malicious files, and used a web execution endpoint to alter server configurations, deploy relays, and piece together custom malware.
Investigators recovered a bespoke tool, tailored to Bitget’s wallet withdrawal logic, which was deleted after use. The tool executed fraudulent asset transfers starting at 01:49 a.m. on September 25. Evidence suggests a web shell was planted on a security appliance (dubbed Product B), through which the attackers established command-and-control channels, moved laterally, deployed malicious packages, and ultimately corrupted Bitget’s wallet job server.
Who Did It
Bitget, alongside analytics firms Elliptic and TRM Labs, points to a North Korean threat actor. This assessment is based on wallet overlaps used in laundering proceeds, drawing from past hacks tied to such groups.�
Implications
In total the hack affected millions in value, disrupted operations due to halted withdrawals, and raised serious red flags about third-party vendor security. Bitget confirmed that components from vendors — Products A and B — were used to bridge into the platform.
Digital asset monitors such as Circle, Tether and NEAR Intents have since frozen approximately $632,700 worth of stolen assets.
This episode follows a growing trend: cryptocurrency platforms under growing pressure from external software vulnerabilities rather than only direct misconfigurations or insider threats.