Bitget Loses $387.5 Million to Hackers Exploiting Zero-Day in Third-Party Security Tools

Cryptocurrency exchange Bitget reveals that hackers who stole $387.5 million last week breach its systems by exploiting a zero-day vulnerability in third-party security products. Two separate investigations by blockchain security firm SlowMist and Google Cloud's Mandiant find that the attackers compromise two security appliances to gain access to Bitget's wallet environment. The attackers then deploy web shells on one appliance and malware on the production wallet job server, along with a custom withdrawal tool used to launch the theft.

SlowMist traces the earliest malicious activity to August 31, when a hidden script on one compromised node reads an environment variable containing a database password. Mandiant reports that on September 24, the threat actor gains privileged access to the security appliances, establishes command-and-control, and moves laterally to the wallet job server. The crypto theft spans nearly three hours in the early hours of September 25, moving funds across multiple blockchains.

Bitget suspends all withdrawals after detecting unauthorized transfers from its hot and warm wallets. CEO Gracy Chen confirms the incident affects multiple assets, including ETH, XRP, BNB, AVAX, USDT, and USDC, across chains such as Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. She blames North Korean hackers for the attack, citing IP behavior patterns and on-chain analysis as evidence.

Read More at the original source →