Skip to main content

Morning Overview

A zero-day in a security product let thieves move $387.5 million out of a crypto exchange

Between 02:31 and 05:23 UTC+8 on September 25, attackers moved $387.5 million out of Bitget’s hot and warm wallets in a window of under three hours. The way in was a zero-day vulnerability in a third-party security product running inside the exchange’s own network, according to Bitget and the two forensic firms it hired. Cold wallets and private keys were left untouched.

No report has named the vendor. Investigators call it Product A, and a second appliance, labelled B, shows up later in the chain.

Product A, a hidden script and a database password

SlowMist, the blockchain security firm brought in by Bitget, laid out the first step in plain terms. In its report, as BleepingComputer relayed it, a service on one of Product A’s nodes was hit by a zero-day; the attacker ran a hidden script under that service process, issued a command that read the environment variable holding the database password, and connected to the database. Nothing in that sequence required guessing a login. The secret was sitting in the process environment, and the zero-day handed over the process. Environment variables are a common place to park credentials because they keep passwords out of source code, which also means anyone who gains code execution inside the service can read them with a single command.

The earliest malicious activity SlowMist could trace goes back to August 31, nearly four weeks before the money moved. Bitget’s timeline puts the first unauthorized transfers at 18:31 UTC on September 24, which is the same instant as the 02:31 UTC+8 start of the window BleepingComputer reports.

Mandiant, the second firm, described the next stage. Its analysis found that the intruders placed a web shell on security appliance B, set up a command-and-control connection, and then moved laterally into the production environment until they controlled the wallet job server, The Hacker News reported. Attackers who hold that server do not have to break any wallet’s cryptography; they only need to speak to the system that decides which withdrawals are legitimate, and every later step in the theft ran through that one trusted channel.

That is what the recovered tooling did. SlowMist found a custom program that, in the words of its summary, forged risk-control parameters, constructed withdrawal requests and invoked the withdrawal process, Cointelegraph reported. Chief executive Gracy Chen made the same point during a livestream on X, saying the attackers corrupted a backend system so that fraudulent withdrawals looked legitimate, rather than stealing private keys.

Thirteen assets across eleven blockchains

Bitget’s own incident page puts the loss at roughly $388 million across 12 wallet addresses, spanning 13 assets on 11 chains: Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand and Celestia. The exchange says no further unauthorized transfers followed containment, that user account balances were not affected, and that its separate non-custodial Bitget Wallet was outside the incident.

The largest single component was XRP. A Gizmodo breakdown lists 102.93 million XRP worth about $157.48 million, 31,890 ETH worth $85.75 million, $34.75 million in USDT and $21.05 million in USDC. Recovery has been thin so far, and Chen has voiced pessimism about getting the rest back: The Hacker News counts nearly $633,000 frozen by Circle, Tether and NEAR Intents, against a Recovery Bounty Program that pays 5 percent to anyone who helps freeze or return funds.

Bitget says a Protection Fund absorbs the financial impact, so customer balances were not reduced. Withdrawals were paused while the exchange kept trading and deposits running, and the incident page reports that BTC and ETH withdrawals came back in phases starting September 28 and 29, with other assets scheduled to follow.

North Korean attribution and the Lazarus pattern

Chen told listeners that IP addresses used in the intrusion matched the VPN habits of a North Korean group. Elliptic, the blockchain analytics firm, assessed a link as highly likely, pointing to on-chain ties between the stolen XRP and earlier thefts attributed to Pyongyang, including the 2025 Bybit heist, and MetaMask security researcher Taylor Monahan named Lazarus as the probable actor. Fortune’s account of the livestream describes the theft as the largest crypto hack of 2026 so far, ahead of a $319 million Liquid Network breach earlier in September and a $116 million Coldcard attack in July, according to Fortune.

The scale matters for context as well. Chainalysis data cited by Fortune put North Korean-linked theft at a record $2 billion in 2025, and the $387.5 million taken from Bitget equals nearly a fifth of that annual total.

SlowMist’s report leaves one gap open: the firm has said its investigation is still working out how the attacker crossed from Product A to the second security product, and the vendor behind both remains unnamed.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview