Cryptocurrency exchange Bitget has confirmed that the $387.5 million drained from its hot and warm wallets late last month was the result of a zero-day vulnerability in third-party security infrastructure, not a flaw in Bitget's own platform.
What happened
According to Bitget's own investigation and supporting analysis from blockchain security firm SlowMist and Google-owned Mandiant, attackers first gained a foothold through a previously unknown vulnerability in a security appliance running on the exchange's network as early as August 31. A hidden script running under a legitimate service process read an environment variable containing a database password and used it to reach internal systems.
Over the following weeks, the intruders repeated the technique against additional nodes, then pivoted to a second security product's management console using a compromised employee identity. From there they abused the platform's web execution endpoint to rewrite server configuration, stand up a communications relay, and assemble malicious binaries in batches — ultimately deploying a web shell and a command-and-control channel on one of the compromised appliances.
That persistence gave the attackers a path to Bitget's production wallet job server. Analysis describes a custom-built tool, tailored specifically to the exchange's withdrawal logic, that began executing fraudulent transfers at 01:49 local time on September 25 — issuing withdrawal commands that bypassed Bitget's existing risk controls across 11 blockchains, including Ethereum, TRON, BNB Smart Chain, Arbitrum, Optimism, Base, Avalanche, Algorand and Celestia.
Bitget temporarily froze all withdrawals once the activity was detected, and roughly $1.1 million of the stolen funds have since been frozen by Circle, Tether and NEAR Intents. Bitget has notified the affected third-party vendor, disabled the vulnerable functionality, and says a fix is pending.
Why it matters
This incident is a reminder that an exchange's security perimeter extends well beyond its own code. Here, the initial compromise happened entirely inside trusted security tooling — the exact products meant to detect intrusions became the entry point. Once inside, the attackers didn't need to break the wallet system's cryptography; they needed working credentials, valid-looking commands, and enough internal trust to bypass the controls meant to catch abnormal withdrawals.
Attribution adds another layer of concern: Bitget says IP behavior and on-chain tracing — corroborated by wallet-overlap analysis from chain-analysis firms — point to North Korean state-linked actors, who have laundered proceeds through infrastructure tied to previous large-scale crypto heists. For any organization holding digital assets, that signals a well-resourced, patient adversary willing to spend weeks inside security infrastructure before touching a single wallet.
What to do
- Inventory and monitor third-party security appliances as attack surface in their own right, not just defensive tooling — apply the same patching cadence, network segmentation, and log review you'd apply to internet-facing services.
- Restrict and monitor service-account access to secrets, especially database credentials reachable via environment variables; a compromised process should never have a direct path to withdrawal infrastructure.
- Enforce least privilege on wallet withdrawal systems, with anomaly detection tuned to catch abnormal transfer patterns even when the request carries valid internal credentials.
- Treat employee identity compromise as a standing risk on admin consoles and management platforms — require step-up authentication and command-level auditing on any endpoint that can write server configuration or execute code.
- Maintain incident response relationships with chain-analysis firms to accelerate freezing and tracing stolen funds across bridges and exchanges.
