// AI threat desk · 4 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesMediumWALLETCVSS not assigned

Bitget wallet flaw exploited to issue $387.5 million in withdrawals

Bitget said attackers used a zero-day in third-party security products to issue fraudulent withdrawals and move $387.5 million from hot and warm wallets. MoneyCheck published it on Sep 25, 2026.

stock image, not from the event
File photo: stock image, not from the event. Photo: Joel-image-Graphics23 / Pixabay
Key takeaways
  • Bitget said attackers used a zero-day in third-party security products to obtain high-level internal credentials and issue fraudulent withdrawal commands.
  • Bitget said unauthorized transfers moved $387.5 million from its hot and warm wallets.
  • Bitget said it disabled the affected functionality and remediated the vulnerability, with no further unauthorized transfers identified after containment.

Bitget said attackers exploited a zero-day flaw in third-party security products and used the access to issue fraudulent withdrawal commands from its wallet system. The exchange disclosed the unauthorized transfers on Sep 24, 2026.

The transfers affected Bitget’s hot and warm wallets and bypassed existing risk controls. Bitget said the attack involved $387.5 million, while The Hacker News said the affected activity covered 11 blockchains.

Gracy Chen said Bitget’s private keys and cold wallets were not compromised. Bitget also said its User Protection Fund held more than $464 million to cover the estimated losses.

On this page

The attack reached Bitget’s wallet job server through a security appliance

Mandiant said the threat actor deployed a web shell on security appliance B, established a command-and-control connection and moved laterally to Bitget’s production wallet job server, where it deployed malicious packages.

SlowMist said a service on Product A’s node was affected by a zero-day vulnerability. It said the attacker ran a hidden script under the service process, read an environment variable containing the database password and connected to the database.

SlowMist said the earliest malicious activity linked to the hack dated to Aug. 31, 2026. It later verified an earliest transfer at 2:31 a.m. UTC+8 on Sep 25, when an attacker-controlled address received 93 TRX.

A recovered tool forged controls and built withdrawal requests

Gracy Chen said the attacker tested the compromised infrastructure at 18:31 UTC with two small unauthorized transfers: 0.184 ETH from an Ethereum hot wallet and 193 TRX from a Tron wallet.

Chen said 17 larger transactions then ran between 18:58 UTC and 20:09 UTC across Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche, transferring about $361 million.

Bitget blocked withdrawals, then reopened Bitcoin withdrawals

Bitget said its reconciliation system identified a major discrepancy at 19:05 UTC, seven minutes after the larger withdrawals began. The exchange then blocked user-initiated withdrawals across the platform.

Bitget said withdrawal services were suspended during security assessments, while deposits and trading continued operating.

Bitget reopened Bitcoin withdrawals on the Bitcoin network at 08:00 UTC on Sep 28, as scheduled.

Bitget said IP behavior patterns and on-chain analysis indicated North Korean threat actors carried out the attack. The Hacker News said Circle, Tether and NEAR Intents froze close to $1.1 million in cryptocurrency assets.

The loss estimate rose after additional transactions were found

Bitget initially estimated affected assets at $351.6 million. FinanceFeeds reported that reconciliation raised the estimate to approximately $387.5 million after additional Zcash and TRON transactions were identified.

Bitget said it notified the relevant third-party vendor, disabled the affected functionality while awaiting a fix, and remediated the vulnerability. It said no further unauthorized transfers were identified after containment.

SlowMist said its investigation remained ongoing and that it was still examining how the attacker moved between affected systems.

FAQ

What happened to Bitget’s wallets?

Bitget said attackers exploited a zero-day in third-party security products, obtained high-level internal credentials and issued fraudulent withdrawal commands that moved $387.5 million from hot and warm wallets.

Which Bitget systems and blockchains were affected?

Mandiant said the attack reached Bitget’s production wallet job server. The Hacker News said the incident affected 11 blockchains, including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand and Celestia.

Were Bitget’s private keys or cold wallets compromised?

Gracy Chen said Bitget’s private keys and cold wallets were not compromised.

How did the Bitget attack issue withdrawals?

SlowMist said the recovered tool forged risk-control parameters, constructed withdrawal requests and invoked the withdrawal process. Bitget said the attackers used high-level internal credentials to issue the commands.

Did Bitget fix the vulnerability?

Bitget said it notified the relevant third-party vendor, disabled the affected functionality, remediated the vulnerability and identified no further unauthorized transfers after containment.

Who did Bitget identify as the attackers?

Bitget said IP behavior patterns and on-chain analysis indicated North Korean threat actors carried out the attack.

Sources

  1. Bitget Confirms $351.6 Million Security Breach Targeting Hot Wallet Infrastructure - MoneyCheck, BitgetPrimary
  2. Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft, The Hacker News
  3. Bitget hacked via zero-day in third-party security products, BleepingComputer
  4. SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit, Cointelegraph
  5. Bitget Withdrawals Resume in Phases After $388 Million Exploit, Blockonomi
  6. Bitget Hacker Used Zero-Day and Test Transfers Before $388M Drain, FinanceFeeds
How we checked this story
ClaimSourceStatus
Bitget said attackers stole $387.5 million last week by exploiting a zero-day flaw in third-party security products.Bitget, via The Hacker NewsAttributed
Bitget said attackers obtained high-level internal credentials and used them to issue fraudulent withdrawal commands.Bitget, via The Hacker NewsAttributed
Bitget said abnormal transfers bypassed existing risk controls.Bitget, via The Hacker NewsAttributed
Bitget disclosed on September 24, 2026, that unauthorized transfers stole $387.5 million from its hot and warm wallets.Bitget, via The Hacker NewsAttributed
Bitget notified the relevant third-party vendor and disabled the affected functionality while awaiting a fix.Bitget, via The Hacker NewsAttributed
The Hacker News said the incident affected 11 blockchains.The Hacker NewsAttributed
SlowMist said the earliest malicious activity linked to the hack dates to August 31, 2026.SlowMist, via The Hacker NewsAttributed
Mandiant said attackers deployed a web shell on security appliance B and moved laterally to Bitget’s production wallet job server.Mandiant, via The Hacker NewsAttributed
Bitget said IP behavior patterns and on-chain analysis indicated North Korean threat actors carried out the attack.Bitget, via The Hacker NewsAttributed
BleepingComputer reported that Bitget said attackers breached its systems after exploiting a zero-day in third-party security products.Bitget, via BleepingComputerAttributed
SlowMist traced the earliest logged malicious activity linked to Bitget’s theft to August 31, when an attacker exploited a third-party product zero-day.SlowMist, via CointelegraphAttributed
SlowMist said its investigation remained ongoing and that it was still examining how the attacker moved between affected systems.SlowMist, via CointelegraphAttributed
SlowMist said the recovered tool forged risk-control parameters, constructed withdrawal requests and invoked the withdrawal process.SlowMist, via CointelegraphAttributed
SlowMist verified the earliest transfer at 2:31 a.m. UTC+8 on September 25, when an attacker-controlled address received 93 TRX.SlowMist, via CointelegraphAttributed
Cointelegraph reported that Bitget CEO Gracy Chen said private keys and cold wallets were not compromised.Gracy Chen, via CointelegraphAttributed
Bitget said it remediated the vulnerability and identified no further unauthorized transfers after containment.Bitget, via BlockonomiAttributed
Gracy Chen said the attacker tested the compromised infrastructure at 18:31 UTC with two small unauthorized transfers.Gracy Chen, via FinanceFeedsAttributed
Bitget’s reconciliation system identified a major discrepancy at 19:05 UTC and the exchange blocked user-initiated withdrawals.Bitget, via FinanceFeedsAttributed
Bitget suspended withdrawals while conducting security assessments, while deposits and trading continued operating.BitgetAttributed
Bitget’s User Protection Fund held more than $464 million to cover the estimated losses.BitgetAttributed
moneycheck.com published its report on Sep 25, 2026.moneycheck.comConfirmed

Could not verify

  • Whether the zero-day has been assigned a CVE is not established
  • Whether the suspected North Korean attribution is supported by evidence beyond the reported IP and on-chain analysis is not established
  • How many users or accounts were affected is not established
  • Whether the third-party products or vendors have been publicly identified is not established
Explore with AI