Bitget Lost $387.5M After Zero-Day in Third-Party Security Appliances
A zero-day in two third-party security appliances gave attackers privileged access to Bitget's wallet environment. Mandiant and SlowMist traced lateral movement to the production wallet job server, where a custom withdrawal tool moved $387.5 million.
Beat this week
Last 7 days · Vulnerabilities
Impact 7.7/10 (+1.7 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.
This story sits in Vulnerabilities — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- A zero-day in two third-party security appliances gave attackers privileged access to Bitget's wallet environment.
- Mandiant and SlowMist traced lateral movement to the production wallet job server, where a custom withdrawal tool moved $387.5 million.
- BleepingComputer
- thehackernews.com
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Attackers stole $387.5 million from Bitget's hot and warm cryptocurrency wallets.
- 2The breach began with zero-day vulnerabilities in two third-party security appliances, according to SlowMist and Mandiant.
- 3The earliest malicious activity in logs dates to August 31, 2026, with unauthorized privileged access confirmed on September 24, 2026.
- 4Threat actors deployed a web shell on security appliance B, established a C2 connection, and moved laterally to Bitget's production wallet job server.
- 5Theft transfers occurred between 02:31 and 05:23 UTC+8 on September 25, 2026, spanning nearly three hours across multiple blockchains.
- 6Bitget suspended all withdrawals on Thursday after detecting the unauthorized transfers.
Forensic findings indicate that on September 24, 2026, a threat actor gained unauthorised privileged access to Bitget's third party security appliances A and B. The threat actor deployed a web shell onto the security appliance B and established a Command-and-Control (C2) connection.
Investigation findings shared by Bitget
Analysis
For security teams, the Bitget breach is a brutal reminder that the security stack itself can be the attack surface. Threat actors exploited zero-days in two third-party security appliances, then pivoted from appliance B to the production wallet job server using a web shell and C2. This is not a stolen API key or social engineering; it's a live, advanced intrusion chain that defeated defensive tooling.
The breach disclosure by cryptocurrency exchange Bitget on September 30, 2026 reveals a sophisticated intrusion that resulted in the theft of $387.5 million from the platform's hot and warm wallets. According to findings shared by blockchain security firm SlowMist and Google Cloud's Mandiant, attackers did not initially target Bitget's own infrastructure; they exploited zero-day vulnerabilities in two separate third-party security appliances. Those appliances, referred to only as Product A and Product B in the forensic reports, were the initial foothold. Once inside the security appliances, the threat actors established a persistent presence, moved laterally into Bitget's production wallet job server, and deployed a custom withdrawal tool that executed unauthorized transfers across multiple blockchains after midnight on September 25.
The breach disclosure by cryptocurrency exchange Bitget on September 30, 2026 reveals a sophisticated intrusion that resulted in the theft of $387.5 million from the platform's hot and warm wallets.
The forensic timeline is unusually detailed. SlowMist reported that the earliest malicious activity in available logs dates to August 31, when a service running on one of Product A's nodes was hit by a zero-day vulnerability. The attacker ran a hidden script under the service process, read an environment variable containing the database password, and connected to the database. Similar hidden-script activity was observed on two other nodes on September 23 and September 25. Mandiant's findings indicate that on September 24, 2026, a threat actor gained unauthorized privileged access to the third-party security appliances A and B, deployed a web shell onto security appliance B, and established a command-and-control connection. Using that persistent access, the actor moved laterally to Bitget's production wallet job server and deployed malicious packages. The actual theft transfers began at 02:31 UTC+8 on September 25 and ended at 05:23, spanning nearly three hours across multiple blockchains. Bitget suspended all withdrawals on Thursday after detecting the unauthorized transfers.
The use of zero-day vulnerabilities in third-party security products is particularly alarming because such appliances are typically trusted, privileged components of an enterprise network. They are designed to inspect traffic, enforce policy, and monitor for threats, yet in this case they became the attack surface. The threat actor converted a defensive tool into a pivot point, using a web shell on security appliance B to reach the production wallet environment. This represents a supply-chain style exposure even though the compromised products were not part of Bitget's codebase; they were third-party security infrastructure whose compromise opened a privileged path into the exchange. The attackers also deployed malware on the wallet job server and used a custom withdrawal tool, suggesting premeditated targeting of Bitget's transaction processing rather than a generic smash-and-grab.
What to Watch
For the crypto industry, the incident carries significant financial and operational implications. A $387.5 million loss from hot and warm wallets is substantial even by historical exchange breach standards. Withdrawals were suspended while Bitget engaged two forensic firms, a move that may reassure some users but also signals the severity of the compromise. The market impact extends beyond Bitget itself: other exchanges will likely be asked whether their third-party security appliances are segmented, patched, and monitored for anomalous behavior. The roughly month-long gap between the first logged malicious activity on August 31 and the theft on September 25 raises difficult questions about dwell time, monitoring coverage, and whether the security appliances themselves were treated as high-risk assets requiring isolation from production wallet infrastructure.
Looking forward, this breach is likely to accelerate several industry adjustments. Exchanges may review vendor risk programs and impose stricter segmentation between third-party security appliances and wallet systems. Regulators may take a deeper interest in operational resilience and third-party technology dependencies, especially after a zero-day in security tooling enabled a nearly $400 million theft. The forensic reports from SlowMist and Mandiant do not yet identify a specific threat actor, but the technical profile—zero-day exploitation, web shells, covert C2, lateral movement, and custom withdrawal tooling—suggests an advanced, well-resourced operation. The incident underscores that defense-in-depth cannot assume security infrastructure is immune from attack, and that continuous monitoring must extend to the very tools meant to keep organizations safe.
Timeline
Timeline
Earliest malicious activity
Logs show a service on one of Product A's nodes was affected by a zero-day vulnerability; attacker ran a hidden script and accessed a database password.
Additional hidden-script activity
Similar hidden-script activity was observed on two other nodes.
Privileged access to security appliances
Mandiant reports threat actor gained unauthorized privileged access to third-party security appliances A and B, deployed a web shell on appliance B, and established C2.
Crypto theft executed
Theft transfers occurred between 02:31 and 05:23 UTC+8, spanning nearly three hours across multiple blockchains.
Bitget discloses breach
Bitget reveals the zero-day breach and shares findings from SlowMist and Mandiant.
Source cluster
Primary reporting
- BleepingComputerBitget hacked via zero-day in third-party security products
Cite This Page
"Bitget Lost $387.5M After Zero-Day in Third-Party Security Appliances." Cyber Intelligence Brief, October 1, 2026. https://getcyberbrief.com/story/bitget-zero-day-security-appliances-387m
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |