Cryptocurrency exchange Bitget confirmed on Wednesday that the theft of $387.5 million from its hot and warm wallets was facilitated by a zero-day vulnerability in third-party security products. The disclosure follows an investigation by blockchain security firm SlowMist, which identified malicious activity involving these external tools and recovered a customized attacker tool used to initiate unauthorized withdrawals. The incident, first disclosed on September 24, 2026, prompted Bitget to temporarily halt all withdrawals while notifying the affected vendors and disabling compromised functionality.

The attack impacted 11 blockchains, including Ethereum, XRP Ledger, and TRON, affecting assets such as ETH, USDT, and BNB. SlowMist’s analysis revealed that the earliest malicious activity occurred on August 31, 2026, when a service on one vendor node was compromised via the zero-day flaw. Attackers subsequently accessed another product’s management platform using internal employee credentials on September 25, 2026, deploying hidden scripts and modifying server configurations. Approximately $1.1 million in assets have been frozen by Circle, Tether, and NEAR Intents, while Google-owned Mandiant noted lateral movement into Bitget’s wallet environment through compromised security appliances.