Close Menu
NCIJ Network NCIJ Network
    What's Hot

    How Far Will the Canada-EU Lovefest Go?

    September 30, 2026

    Israeli minister claims ‘terrorist’ wanted to crash plane after Tel Aviv-bound flight’s emergency landing – latest | Air transport

    September 30, 2026

    Wie Merz in der Wirtschaft den Macron macht – POLITICO

    September 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How Far Will the Canada-EU Lovefest Go?
    • Israeli minister claims ‘terrorist’ wanted to crash plane after Tel Aviv-bound flight’s emergency landing – latest | Air transport
    • Wie Merz in der Wirtschaft den Macron macht – POLITICO
    • Airbnb adds AI search, more social features
    • AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
    • HANetf Debuts Euro-Hedged Bitcoin Fund In World First
    • Just over a quarter of nurdles cleared after River Tyne spillage
    • Tokyo records historic 35-day rain streak driven by El Niño and stalled fronts
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Bitget hacked via zero-day in third-party security products

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 30, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products.

    According to Bitget, two separate investigations by blockchain security firm SlowMist and Google Cloud’s cyber-defense arm Mandiant said the threat actors accessed Bitget’s wallet environment after compromising two security appliances with zero-day exploits.

    After the breach, the attackers dropped web shells on one of the hacked appliances and malware on the crypto exchange’s production wallet job server, as well as a custom withdrawal tool used to launch the cryptocurrency theft after midnight on September 25.

    “The earliest malicious activity identified in the available logs dates to August 31. A service running on one of Product A’s nodes was affected by a zero-day vulnerability. The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database. Similar hidden-script activity was observed on two other nodes on September 23 and September 25,” SlowMist said.

    “Forensic findings indicate that on September 24, 2026, a threat actor gained unauthorised privileged access to Bitget’s third party security appliances A and B. The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection. Using the persistent access on security appliance B, the threat actor moved laterally to Bitget’s production wallet job server and deployed malicious packages,” Mandiant added.

    SlowMist added that the earliest crypto theft transfer occurred on September 02:31 (UTC+8) and the last took place at 05:23, with the attack spanning nearly 3 hours across multiple blockchains.

    Bitget suspended all withdrawals on Thursday after detecting multiple unauthorized transfers from its hot and warm crypto wallets and discovering that attackers had stolen $387.5 million from them.

    CEO Gracy Chen noted the incident affected multiple assets, including ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens, and involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains.

    Chen also blamed the attack on North Korean hackers, citing IP behavior patterns and on-chain analysis as evidence, and added that they breached a critical backend system within Bitget’s wallet infrastructure that was later used to spoof transaction data, triggering the exchange’s authorization process to move funds out of compromised hot/warm wallets.

    North Korean hackers have been behind many other major crypto heists, including the Bybit hack, in which they stole $1.5 billion from the crypto exchange’s ETH cold wallet.

    Since the breach, Bitget has launched a Recovery Bounty Program that offers bounties of 5% to those who help recover or freeze funds stolen in the attack.

    A Bitget spokesperson was not immediately available when BleepingComputer contacted them earlier today for more information on the zero-day flaw and the third-party security products compromised in the attack.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Bitget Hacked products Security thirdparty ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

    Europe’s energy security has a Black Sea opportunity – POLITICO

    ShinyHunters Defiant After FBI Calls on Members to Come Forward

    Can we jail a superintelligence?

    Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

    High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    How Far Will the Canada-EU Lovefest Go?

    September 30, 2026

    Israeli minister claims ‘terrorist’ wanted to crash plane after Tel Aviv-bound flight’s emergency landing – latest | Air transport

    September 30, 2026

    Wie Merz in der Wirtschaft den Macron macht – POLITICO

    September 30, 2026

    Airbnb adds AI search, more social features

    September 30, 2026
    Latest Posts

    Bitcoin collateral: MARA’s $600M Long Ridge financing

    August 7, 2026

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    August 7, 2026

    The best classic slasher movie you’ll never watch

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    How Far Will the Canada-EU Lovefest Go?

    September 30, 2026

    Israeli minister claims ‘terrorist’ wanted to crash plane after Tel Aviv-bound flight’s emergency landing – latest | Air transport

    September 30, 2026

    Wie Merz in der Wirtschaft den Macron macht – POLITICO

    September 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.