Back to Newsroom
Breach

Bitget Loses $387.5M After Zero-Day Hits Third-Party Security Tools

Bitget says attackers exploited a zero-day in two third-party security appliances to reach its production wallet infrastructure, moving $387.5 million out of hot and warm wallets in under three hours before withdrawals were frozen.

Bitget Loses $387.5M After Zero-Day Hits Third-Party Security Tools

Cryptocurrency exchange Bitget has confirmed that a breach draining $387.5 million from its hot and warm wallets did not start with a flaw in its own trading platform — it started in the security tooling meant to protect it.

What happened

According to forensic reviews of the incident, attackers gained unauthorized access to two of Bitget's third-party security appliances by exploiting a zero-day vulnerability. From there they dropped a web shell and established a command-and-control foothold, then moved laterally into the exchange's production wallet job server. A custom withdrawal tool was used to trigger the theft, with the bulk of transfers compressed into roughly three hours overnight and spread across multiple blockchains, including Ethereum, BNB Chain, Avalanche, Arbitrum, Optimism, and Base.

Early indicators of the intrusion reportedly date back weeks before the payout, suggesting the attackers spent time quietly probing the compromised appliances before making their move. Bitget suspended all withdrawals as soon as the unauthorized transfers were detected, and its leadership has since attributed the operation to a state-linked threat actor associated with previous large-scale exchange heists, citing infrastructure and on-chain transfer patterns as supporting evidence.

Why it matters

This breach fits a pattern security teams are seeing more often: attackers bypassing an exchange's front-line defenses entirely by going after the third-party tools sitting inside the perimeter — the very appliances deployed to secure production systems. Once one of those tools is compromised, it can become a direct pivot point into infrastructure holding hundreds of millions of dollars in customer funds, with no phishing, credential theft, or insider involvement required.

What to do

  • Treat every security appliance, monitoring agent, and third-party tool as part of your attack surface — patch and monitor it with the same urgency as production systems, not less.
  • Segment wallet job servers and withdrawal infrastructure from general security-tooling networks so a single compromised appliance cannot reach custody systems directly.
  • Watch for anomalous service-account behavior — unexpected environment-variable reads or database connections from processes that shouldn't be making them — since these often surface weeks before a payout.
  • Keep an incident response plan that can freeze withdrawals within minutes of detecting abnormal transfer patterns, and rehearse it.
  • If you operate exchange or custodial infrastructure, define a rapid recovery/bounty process in advance so it can be activated the moment a theft is confirmed.
SHARE