Security

SlowMist and Mandiant trace Bitget $387.5M theft to zero day security flaw

Interim forensic reports from SlowMist and Google Cloud's Mandiant say the attacker who took $387.5 million from Bitget spent almost four weeks inside third party security products before any funds moved.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 30, 2026 / 7 min read

Bitget, the Seychelles-based cryptocurrency exchange, disclosed on September 24, 2026 that unauthorized transfers had drained roughly $387.5 million from parts of its hot and warm wallets. The exchange's monitoring systems flagged the movement at 18:31 UTC, and withdrawals were suspended within minutes as the company activated emergency procedures. The exchange said the affected assets included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX, with XRP accounting for the largest single share.

Nearly a week later, on September 30, 2026, blockchain security firm SlowMist and Google Cloud's cyber-defense arm Mandiant published interim forensic findings that reshaped the public understanding of the incident. The two investigations concluded that the attacker never obtained private keys. Instead, the intruder compromised third-party security products, in one case through a zero-day vulnerability, then moved laterally into Bitget's wallet environment.

The timeline the firms described reaches back far earlier than the moment funds left the exchange. According to SlowMist, the earliest malicious activity dates to August 31, 2026, on a node of a system it calls Product A, almost four weeks before the theft. Mandiant separately said the attacker gained unauthorized access to certain third-party security appliances before moving into the wallet environment and obtaining access to warm and hot wallets, and it found no evidence that private keys leaked. Bitget has said the intrusion hit some hot and warm wallets while offline cold wallets and the separate Bitget Wallet self-custody product were unaffected.

Bitget had already begun describing the attack path in public. Crypto Briefing reported on September 28 that CEO Gracy Chen said the attacker exploited vulnerabilities in third-party products to obtain internal credentials, then used those credentials to issue fraudulent withdrawal commands that bypassed the exchange's risk controls. She said private keys were not compromised and cold wallets were not affected, and she described the breach as Bitget's first security incident of this nature in eight years.

Key Facts

The Crypto Times reported on September 30 that the interim findings show attackers held a foothold inside parts of Bitget's infrastructure almost four weeks before any funds moved. SlowMist traced the first malicious activity to August 31, when a zero-day in Product A allowed a hidden script running under the service process to read database passwords and environment variables. That access predates the theft by nearly a month.

SlowMist also found that the attacker gained unauthorized access on September 25 (UTC+8) to a third-party product management platform by using an internal employee identity, and that investigators recovered a highly customized withdrawal tool built around the wallet system's withdrawal logic. On-chain transfers began at 02:31 on September 25 (UTC+8) and ran for about 2 hours and 52 minutes, ending near 21:23 UTC, with later attempts to alter withdrawal records and trigger additional Bitcoin withdrawals.

BleepingComputer reported on September 30 that the two investigations examined two compromised security appliances, with attackers dropping web shells on one of them. Neither firm has named the vendors or products involved, and there is no public CVE, vendor advisory or list of affected versions to patch against. SlowMist refers to the affected systems as Product A and Product B, and the appliance that was not reached through the zero-day was compromised through an internal employee identity instead.

Coinpedia reported on September 25 that Bitget first estimated the loss at $351.6 million, disclosed around 21:30 UTC on September 24. By 14:03 UTC on September 25 the exchange had revised the figure to $387.5 million after adding Zcash and TRON transfers from the same attack window, describing the change as a reconciliation rather than a second breach. Chen cited IP behavior and blockchain activity consistent with North Korean groups, though the initial entry point was not disclosed at that stage.

Crypto Briefing reported on September 28 that Bitcoin withdrawals had resumed with 9,585 orders totaling 4,098.036 BTC as of 17:00 UTC+8. The exchange said it had isolated the affected systems and servers, revoked and reissued internal credentials, restructured access to highly sensitive infrastructure and disabled the affected functionality. Mandiant and SlowMist continued to support the forensic investigation.

Analysis

What this really means is that the perimeter that crypto exchanges have spent years hardening is no longer the perimeter that matters most. Bitget's own account, echoed by Mandiant and SlowMist, is that the attacker never needed a private key. The intruder obtained internal credentials and then let Bitget's own authorization process approve transfers that the exchange's systems accepted as valid, a pattern that turns the exchange's trust infrastructure into the weapon.

The bigger picture here is that dwell time is now the decisive metric. The near four-week gap between the August 31 activity and the September 24 theft is the detail that should worry security teams most. Detection at the exchange occurred only when funds moved, not when the intrusion began. Investigators recovered a custom withdrawal tool built specifically around the wallet system's withdrawal logic, which points to preparation rather than opportunism, and the on-chain theft itself lasted about 2 hours and 52 minutes.

The unresolved question is vendor accountability. Because no vendor has been named and no CVE exists, every exchange running similar third-party security appliances has no patch to apply and no version list to check. That absence of a public advisory keeps the exposure invisible until someone else is hit.

Chen's suspicion of North Korean involvement, based on IP behavior and blockchain activity, adds a state-linked dimension that exchanges cannot patch away. Coinpedia noted that several details resemble the February 2025 Bybit theft, including manipulated approvals, rapid asset conversion, wallet splitting and the use of THORChain. Analyst DCF GOD flagged a fresh wallet spending $19.67 million in USDT0 to purchase 7,111 ETH within six minutes at up to 5 percent above market prices, and Bubblemaps reported roughly $180 million moving from Bitget wallets to a common receiving address before being split across several wallets.

Why It Matters

User balances were unaffected, and Bitget said losses would be covered by its Protection Fund, which held more than $464 million when the incident was first disclosed. That cushion matters because the $387.5 million loss amounts to roughly 83.5 percent of the fund's value at disclosure. Chen said the exchange would replenish the fund with its own capital to bring it back above $300 million within a week.

Recovery on the blockchain side has been partial. THORChain declined Chen's request to refuse service to attacker-linked addresses, while NEAR Intents said it blocked more than $50 million in attempted laundering flows but froze only about $503,000. Bitget offered a 5 percent bounty on eligible freezes and recoveries.

Operationally, the exchange restarted in phases. Bitcoin withdrawals went live on the Bitcoin network and BNB Smart Chain on September 28, and The Crypto Times reported on September 29 that Ether withdrawals resumed at 08:00 UTC that day, with about 9,674 ETH in inflows against about 9,023 ETH in outflows by 09:00 UTC, a net inflow of roughly 651 ETH in the first hour. USDT on Ethereum, BSC, Solana and Tron was scheduled for September 30, with other tokens, fiat and peer-to-peer flows set for October 2.

Next Up

The interim findings leave several threads open. Neither SlowMist nor Mandiant has named the security vendors, and the absence of a public CVE means patches and mitigation guidance may take longer to reach other operators. Chen has described the breach as Bitget's first security incident of this nature in eight years, and the exchange continues to publish updates as the remaining withdrawal phases complete.

Investigators will also be watching the attacker's remaining funds. Attempts to alter withdrawal records and trigger additional BTC withdrawals were part of the activity SlowMist documented, and the on-chain trail runs from a common receiving address to multiple wallets after roughly $180 million was moved from Bitget wallets. Whether the more than $50 million in blocked laundering flows or the small frozen balance can be expanded is likely to shape the next forensic update.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.