Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Should we refuse to give the Bayeux tapestry back to France? Of course not! So why are we keeping the Parthenon marbles? | Simon Jenkins

    October 2, 2026

    Washington’s diplomacy in Sudan has backfired | Opinions

    October 2, 2026

    Tories warn Burnham’s EU ‘pandering’ will shred post-Brexit trade deals – POLITICO

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Should we refuse to give the Bayeux tapestry back to France? Of course not! So why are we keeping the Parthenon marbles? | Simon Jenkins
    • Washington’s diplomacy in Sudan has backfired | Opinions
    • Tories warn Burnham’s EU ‘pandering’ will shred post-Brexit trade deals – POLITICO
    • Election Deniers Think the GOP’s Terrible Midterm Polling Is a ‘Psyop’
    • Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
    • US moves to choke off Russia’s $17 billion A7 network
    • Bats may have first evolved in Europe 65 million years ago
    • As fires spread, Indonesia’s rubber growers draw on traditional ways to fight back
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 1, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist.

    “Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker to initiate unauthorized withdrawals,” Bitget said in a post on X.

    On September 24, 2026, the cryptocurrency exchange disclosed that threat actors stole $387.5 million from its hot and warm wallets through a series of unauthorized transfers, prompting it to halt all withdrawals temporarily. Close to $632,700 in cryptocurrency assets have been frozen by Circle, Tether, and NEAR Intents.

    In a subsequent analysis, Bitget said the attackers exploited the flaw to obtain high-level internal credentials and use them to issue fraudulent withdrawal commands to the wallet system and initiate “abnormal transfers that bypassed existing risk controls.” Bitget has since notified the relevant third-party vendor and disabled the affected functionality pending completion of a fix.

    Cybersecurity

    The incident impacted 11 blockchains, including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. Affected assets identified to date include XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, and TIA.

    According to a new progress report published by SlowMist, the earliest malicious activity linked to the hack dates back to August 31, 2026.

    “A service running on one of Product A’s nodes was affected by a zero-day vulnerability,” the company said. “The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database.”

    “Similar hidden-script activity was observed on two other nodes on September 23 and September 25. These findings show that the affected service environments had already been compromised before the assets were transferred out.”

    Then, on September 25, 2026, the threat actor is said to have accessed another product’s (named Product B) management platform by using an internal employee’s identity and making three consecutive attempts to inject system commands into the product’s task parameters to write malicious files.

    “The attacker subsequently submitted code through the platform’s web execution endpoint, attempting to modify server configuration, write a communication relay file, and upload and assemble malicious program files in batches,” the blockchain security company added.

    Another key finding relates to the threat actor’s use of a bespoke tool to siphon the assets. SlowMist said the program was among the deleted files it had recovered. Highly tailored to the wallet system’s withdrawal logic, the tool began running and executing cryptocurrency theft at 01:49 a.m on September 25, 2026.

    Cybersecurity

    Google-owned Mandiant’s probe into the incident has found that the attackers gained unauthorized access to certain third-party security appliances (i.e., A and B), and then leveraged that access to move laterally into Bitget’s wallet environment.

    “The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection,” Mandiant said. “Using the persistent access on security appliance B, the threat actor moved laterally to Bitget’s production wallet job server and deployed malicious packages.”

    “The threat actor compromised network and security appliances and leveraged them to distribute malicious packages and gain control over the wallet job server.”

    Bitget said IP behavior patterns and on-chain analysis indicate the attack was carried out by North Korean threat actors, with Elliptic and TRM Labs uncovering wallet overlaps used to launder illicit proceeds obtained from previous hacks.

    Bitget Confirms cryptocurrency Million theft thirdparty ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

    Bats may have first evolved in Europe 65 million years ago

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    Rolling the cyber dice with open-source and open-weight AI models

    Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    Microsoft says threat actors are ahead in the early AI race

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Should we refuse to give the Bayeux tapestry back to France? Of course not! So why are we keeping the Parthenon marbles? | Simon Jenkins

    October 2, 2026

    Washington’s diplomacy in Sudan has backfired | Opinions

    October 2, 2026

    Tories warn Burnham’s EU ‘pandering’ will shred post-Brexit trade deals – POLITICO

    October 2, 2026

    Election Deniers Think the GOP’s Terrible Midterm Polling Is a ‘Psyop’

    October 2, 2026
    Latest Posts

    Max Miller Continues to Resist Pressure to Drop Out as Deadline Looms

    August 7, 2026

    Houthi attacks kill at least 10 in Yemen as rebels target oil-rich Marib

    August 8, 2026

    Scientists find unexpected life on Ötzi the Iceman’s 5,300-year-old body

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Should we refuse to give the Bayeux tapestry back to France? Of course not! So why are we keeping the Parthenon marbles? | Simon Jenkins

    October 2, 2026

    Washington’s diplomacy in Sudan has backfired | Opinions

    October 2, 2026

    Tories warn Burnham’s EU ‘pandering’ will shred post-Brexit trade deals – POLITICO

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.