Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Crypto

Bitget $387.5M hack traced to third-party zero-day

Attackers were inside Bitget for 25 days before draining hot and warm wallets across 11 blockchains, investigators SlowMist and Mandiant say.

By · Published · Updated · 6 min read

Padlock image for the Bitget cryptocurrency exchange hack

Cryptocurrency exchange Bitget has confirmed that the attackers who stole $387.5 million on September 24 got in through a zero-day vulnerability in third-party security software, The Hacker News reports.

Timeline of the attack

Interim findings from SlowMist and Mandiant show the attackers had a foothold long before any money moved:

  • August 31: a service on a third-party security product ("Product A") is compromised through a zero-day. A hidden script reads a database password from an environment variable, according to SlowMist.
  • September 23–25: the same activity appears on two more nodes.
  • September 24: the attacker logs in with an internal employee's identity and uses a custom withdrawal tool that forged risk-control parameters. Funds drain for 2 hours and 52 minutes, Bitcoin.com reports.

That 25-day gap between initial access and the theft is the most alarming detail. The attackers spent weeks mapping the exchange's internal systems, learning how withdrawals were approved and building a tool specifically to defeat them. By the time money moved, every step looked legitimate to Bitget's own controls.

No private keys were stolen. Instead, the attackers made withdrawals the exchange's own systems accepted as valid.

Scale of the theft

The theft hit 11 blockchains including Ethereum, XRP Ledger, TRON, Base and BNB Smart Chain. Only about $632,700 has been frozen by Circle, Tether and NEAR Intents — a small fraction of the total, illustrating how quickly stolen crypto disperses beyond reach once it starts moving across chains.

Bitget's cold wallets and its separate Bitget Wallet app were not affected. The exchange has said users will be covered, and its protection fund — publicly verifiable on-chain — is large enough to absorb the loss, which likely prevented the kind of bank-run panic that has destroyed smaller exchanges after hacks.

Analytics firm Elliptic linked the attack to North Korea, saying it pushes the country's crypto thefts this year past $1 billion, Bloomberg Law reported.

The North Korea connection

If the attribution holds, Bitget joins a long list of exchanges hit by North Korean operators, who have made crypto theft a significant source of hard currency for the sanctioned state. Their playbook has evolved: rather than attacking cryptography directly, they target the people and software around it — fake job applicants, compromised vendors, poisoned updates and, as here, flaws in the security products an exchange relies on.

Why it matters

The security products meant to protect Bitget became the way in. It is the same lesson as the 2025 Bybit theft: attackers no longer need to crack wallet keys if they can control the systems that approve withdrawals. Every vendor with access to your environment is part of your attack surface, and a zero-day in one of them can undo millions spent on your own defenses.

For the wider industry, the incident will renew pressure on exchanges to publish real-time proof of reserves and to treat third-party software with the same suspicion they apply to external attackers.

What crypto users should do

  • Keep long-term holdings in a wallet you control, not on an exchange.
  • Spread funds across services rather than holding everything in one place.
  • Ignore "Bitget refund" messages — they are a common follow-up scam after large hacks.
  • If you trade actively, enable withdrawal address allowlisting and every available verification step on your account.

Sources

Read next