Bitget Confirms Hackers Used a Hidden Security Flaw to Steal $387 Million
A major cryptocurrency theft at Bitget has taken a new turn after the company confirmed that hackers exploited a previously unknown security flaw in software provided by a third party. The attack resulted in approximately $387.5 million worth of cryptocurrency being transferred out of some of Bitget’s wallets.
The incident happened on September 24, 2026, when Bitget detected unauthorized transfers from some of its digital wallets. The company temporarily stopped withdrawals while it investigated what had happened and worked to secure its systems.
At first, it wasn’t clear how the attackers had managed to get into Bitget’s infrastructure. Investigators from cybersecurity companies Mandiant and SlowMist have since provided more information about the attack, helping to explain how the hackers moved from an outside system into the exchange’s wallet environment.
The attack involved what is known as a “zero-day” vulnerability. Despite the intimidating name, the concept is fairly simple. A zero-day is a security weakness in software that is unknown to the software maker, or at least has not yet been fixed, when attackers discover and use it. Because there may be no available security update when the attack begins, these vulnerabilities can be particularly difficult for organizations to defend against.
In this case, the vulnerability wasn’t found directly in Bitget’s cryptocurrency exchange software. Instead, investigators found that attackers had compromised security products provided by a third-party vendor that Bitget was using.
This is an important part of the story because businesses rarely operate using software they built entirely themselves. Companies often rely on dozens or even hundreds of outside products and services to protect their networks, manage computers, process payments, and perform other tasks.
That means a security problem in one of those outside products can potentially become a security problem for the company using it.
Investigators found evidence that attackers had gained access to one of the third-party security products through the previously unknown vulnerability. From there, they were able to obtain information that helped them access internal systems.
The attackers eventually reached systems involved in Bitget’s cryptocurrency wallet operations. They were then able to manipulate the process used to authorize withdrawals.
Normally, moving cryptocurrency out of an exchange’s wallets involves multiple security checks designed to make sure a transaction is legitimate. The attackers were able to bypass some of those safeguards and issue fraudulent withdrawal instructions.
To put that into everyday terms, imagine a bank where a withdrawal normally requires several employees and security systems to approve a transaction. Instead of stealing someone’s password and logging into their bank account, an attacker finds a weakness in one of the systems used by the bank’s employees to approve transactions. If they can manipulate that system, they may be able to make an unauthorized transaction look legitimate.
That is essentially what happened at Bitget. The attackers didn’t simply steal a user’s password and transfer money from an individual account. They gained access to parts of the infrastructure that controlled the exchange’s own wallet operations.
Investigators also discovered that the attackers had created specialized software specifically designed to interact with Bitget’s withdrawal system. The tool was tailored to the way Bitget processed cryptocurrency withdrawals and was used to carry out the theft.
The stolen assets came from Bitget’s hot and warm wallets. These are cryptocurrency wallets that are connected to systems used to process transactions. Exchanges use them because they need access to funds to handle withdrawals and other day-to-day activity.
Bitget’s cold wallets, which are kept offline and hold the majority of the platform’s assets, were not affected. The company has also said that customer account balances were not affected by the incident and that its Protection Fund will cover the financial impact.
The attack affected multiple cryptocurrency networks, including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. A number of different cryptocurrencies were involved in the unauthorized transfers.
Bitget has since disabled the affected functionality and notified the third-party vendor responsible for the vulnerable software. The company has also taken additional steps to protect its internal systems, including changing credentials, restricting access, adding additional checks around withdrawals, and increasing monitoring for unusual activity.
The investigation also revealed that the attackers had been inside parts of the environment before the actual cryptocurrency transfers took place. According to investigators, suspicious activity connected to the attack dates back to August 31, weeks before the stolen funds were moved.
This highlights an important point about modern cyberattacks: criminals don’t always break into a system and immediately steal something. They may spend days or weeks quietly exploring the environment, finding additional access points, and preparing for the final stage of the attack.
Bitget has also said that its investigation points toward North Korean threat actors, based on patterns in the attackers’ activity and analysis of where the stolen cryptocurrency was moved. Security companies have identified connections between some of the wallets involved in the Bitget incident and wallets associated with previous cryptocurrency thefts attributed to North Korean hacking groups. The investigation is ongoing, however, and the company has not publicly released every technical detail.
Some of the stolen cryptocurrency has already been frozen. Bitget said that cryptocurrency companies and blockchain organizations have helped prevent some of the stolen assets from being moved or converted. The company has also launched a recovery program aimed at helping track down and recover additional funds.
The incident is a reminder that cybersecurity problems don’t always come from the software a company develops itself. Businesses can also be exposed through products supplied by other companies, even when those products are designed to improve security.
For everyday users, this story may seem far removed from their own computers or online accounts. But the underlying lesson applies to almost every organization. Companies depend on networks of outside software and services, and a weakness in one part of that network can sometimes provide attackers with a path into another.
For businesses, the incident reinforces the importance of knowing what third-party software is running inside their environments, keeping those products updated, limiting their access, and monitoring them for unusual behavior. Security tools themselves need to be treated as part of the security perimeter rather than automatically assuming they are safe simply because their purpose is to provide protection.
The Bitget attack also demonstrates why security vulnerabilities can be so valuable to criminals. The attackers didn’t need to find a weakness in every system they wanted to access. They found one vulnerability in a third-party product and used it as a stepping stone toward a much more valuable target.
As organizations become increasingly dependent on technology from outside vendors, these types of attacks are likely to remain an important cybersecurity concern. Protecting a business isn’t just about securing its own software anymore. It also means understanding and managing the security risks that come with the technology supplied by everyone else.







