Executive Summary
On September 24-25, 2026, Bitget, a major cryptocurrency exchange, suffered a theft of $387.5 million in digital assets after attackers exploited a zero-day vulnerability in third-party security products. The breach was confirmed by Bitget and independently investigated by blockchain security firm SlowMist and Google-owned Mandiant. Attackers gained unauthorized access to internal credentials and issued fraudulent withdrawal commands, bypassing existing risk controls and impacting assets across 11 blockchains, including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. The incident highlights the operational and supply chain risks associated with reliance on third-party security tools, especially in high-value environments such as cryptocurrency exchanges. Attribution is assessed as likely North Korean threat actors, based on IP behavior, on-chain analysis, and wallet overlaps with previous attacks. Law enforcement and regulatory responses included the freezing of $1.1 million in assets by Circle, Tether, and NEAR Intents. No public indicators of compromise (IOCs) have been disclosed as of the publication dates.
Technical Information
The attack on Bitget was executed through a sophisticated, multi-stage campaign exploiting a zero-day vulnerability in at least two third-party security appliances, referred to as Product A and Product B. The attackers’ initial access was achieved by exploiting this unknown flaw, which allowed them to run hidden scripts under the service process of Product A. These scripts extracted environment variables containing database credentials, enabling the attackers to connect to internal databases and escalate their privileges.
On September 23 and 25, 2026, similar hidden-script activity was observed on additional nodes, indicating that the attackers had established persistent access across multiple points in the environment. On September 24, 2026, the attackers gained unauthorized privileged access to both security appliances. They deployed a web shell on Product B, establishing a command-and-control (C2) channel for remote access and lateral movement.
Using this persistent access, the attackers moved laterally to Bitget’s production wallet job server, where they deployed malicious packages. They also used a highly tailored, custom withdrawal tool designed to interact with Bitget’s wallet withdrawal logic. This tool was executed at 01:49 a.m. on September 25, 2026, and automated the theft of assets across 11 blockchains over a period of nearly three hours.
The attackers obtained high-level internal credentials, which they used to issue fraudulent withdrawal commands that bypassed existing risk controls. This indicates a deep understanding of Bitget’s internal processes and security architecture. The attack was detected after multiple unauthorized transfers were observed from hot and warm wallets, prompting Bitget to halt all withdrawals and initiate an incident response.
Technical analysis by SlowMist and Mandiant mapped the attack to several MITRE ATT&CK techniques, including T1190 (Exploit Public-Facing Application), T1059 (Command and Scripting Interpreter), T1552.001 (Unsecured Credentials: Environment Variables), T1505.003 (Web Shell), T1021 (Remote Services), T1570 (Lateral Tool Transfer), T1078 (Valid Accounts), T1567 (Exfiltration Over Web Service), and T1562 (Impair Defenses).
No public hashes or technical indicators for the custom tools or malware used in the attack have been disclosed as of the publication dates.
Affected Versions & Timeline
The specific third-party security products exploited in the attack have not been publicly named by Bitget or the investigating firms. The incident timeline is as follows: the earliest malicious activity was detected on August 31, 2026, involving a hidden script on a Product A node. Similar activity was observed on September 23 and 25, 2026. On September 24, 2026, attackers gained unauthorized privileged access to security appliances A and B, deployed a web shell, and established C2. The custom withdrawal tool was executed at 01:49 a.m. on September 25, 2026, with the theft spanning nearly three hours. Bitget detected unauthorized transfers on September 24-25, 2026, halted all withdrawals, and began incident response procedures.
Threat Activity
The threat actors demonstrated advanced capabilities, including the exploitation of a zero-day vulnerability in third-party security appliances, deployment of hidden scripts and web shells, credential theft, lateral movement, and the use of a custom withdrawal tool. The attackers bypassed risk controls and executed unauthorized withdrawals across multiple blockchains and assets, including ETH, XRP, BNB, AVAX, USDT, USDC, ZEC, ATOM, USD0, XAUt, TRX, ALGO, and TIA.
Attribution is assessed as likely North Korean threat actors, based on IP behavior patterns, on-chain analysis, and wallet overlaps with previous North Korean-attributed hacks, as reported by Elliptic and TRM Labs. The attackers’ tactics, techniques, and procedures (TTPs) are consistent with historical campaigns targeting cryptocurrency exchanges.
Mitigation & Workarounds
The following mitigation and workaround recommendations are prioritized by severity:
Critical: Organizations should immediately review the deployment and configuration of all third-party security products, especially those with privileged access to sensitive environments. Ensure that these products are included in vulnerability management and incident response plans, and that vendors provide timely security updates and clear processes for vulnerability disclosure.
High: Monitor all security appliances and critical systems for unusual behavior, including unauthorized script execution, web shell deployment, and abnormal network connections. Implement layered, independent security controls to prevent a single point of failure.
Medium: Assess the security posture of all vendors providing security tools, including their history of vulnerability management and incident response. Confirm that fallback procedures exist in case a security product is compromised.
Low: Regularly review and update incident response plans to include scenarios involving the compromise of security tooling. Participate in sector-specific threat intelligence sharing to stay informed of emerging risks.
Indicators of Compromise
No public indicators of compromise (IOCs) were available at the time of writing. Organizations should monitor for updates from Bitget, SlowMist, Mandiant, and trusted threat intelligence sources, and validate any indicators before enforcement.
References
https://secarma.com/01-10-2026-bitget-zero-day-cryptocurrency-theft (Secarma, Oct 1, 2026)
https://thehackernews.com/2026/10/bitget-confirms-third-party-zero-day.html (The Hacker News, Oct 1, 2026)
https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/ (BleepingComputer, Sep 30, 2026)
About Rescana
Rescana provides a Third-Party Risk Management (TPRM) platform that enables organizations to continuously assess, monitor, and manage the security posture of their vendors and supply chain partners. Our platform supports the identification of operational and supply chain risks associated with third-party security products, facilitates vendor risk assessments, and integrates with incident response workflows to help organizations respond effectively to emerging threats.
We are happy to answer questions at info@rescana.com.



