Cryptocurrency exchange Bitget confirmed on Wednesday that the theft of $387.5 million from its hot and warm wallets was facilitated by a zero-day vulnerability in third-party security products. The disclosure follows an investigation by blockchain security firm SlowMist, which identified malicious activity involving these external tools and recovered a customized attacker tool used to initiate unauthorized withdrawals. The incident, first disclosed on September 24, 2026, prompted Bitget to temporarily halt all withdrawals while notifying the affected vendors and disabling compromised functionality.
The attack impacted 11 blockchains, including Ethereum, XRP Ledger, and TRON, affecting assets such as ETH, USDT, and BNB. SlowMist’s analysis revealed that the earliest malicious activity occurred on August 31, 2026, when a service on one vendor node was compromised via the zero-day flaw. Attackers subsequently accessed another product’s management platform using internal employee credentials on September 25, 2026, deploying hidden scripts and modifying server configurations. Approximately $1.1 million in assets have been frozen by Circle, Tether, and NEAR Intents, while Google-owned Mandiant noted lateral movement into Bitget’s wallet environment through compromised security appliances.
This incident highlights the critical supply chain risks inherent in cryptocurrency infrastructure, demonstrating how vulnerabilities in third-party security appliances can bypass primary exchange defenses. By exploiting zero-day flaws in external tools, attackers gained high-level internal credentials and issued fraudulent withdrawal commands that circumvented existing risk controls. This underscores the fragility of perimeter security when dependent on unpatched or vulnerable third-party components, shifting the focus from direct exchange breaches to indirect compromise vectors within the operational ecosystem.
From an institutional adoption perspective, the attribution of this large-scale theft to North Korean threat actors, supported by Elliptic and TRM Labs’ identification of wallet overlaps, reinforces the persistent state-sponsored nature of crypto crime. The ability of attackers to move laterally from security appliances to production wallet servers indicates sophisticated operational tradecraft that challenges standard compliance frameworks. Institutions must now scrutinize not only their own codebases but also the integrity and patching status of every third-party integration, as the distinction between internal and external attack surfaces has effectively dissolved.


