The Attack That Took $387.5 Million from Bitget Came in Through a Security Product, Not the Exchange
The $387.5 million Bitget theft, disclosed on 24 September, did not exploit a flaw in the exchange's own code. It exploited a zero-day in a third-party security product, which handed the attacker internal credentials to issue withdrawals that slipped past risk controls. Cold wallets were untouched and, according to Bitget, a protection fund covers the loss. Attribution points, with caveats, to North Korea.

▸In this article
The cryptocurrency exchange Bitget has confirmed that the attackers who took $387.5 million from it did not get in through a hole in its own systems. They got in through a zero-day in a third-party security product — the kind of tool meant to guard the house. That inversion is what sets this case apart from the usual exchange heist: the defensive tool was the attack vector.
The figure grew along the way. On 25 September, on-chain analytics firms TRM Labs and Elliptic put the loss at $351.6 million. Bitget itself revised the number to $387.5 million once the count was complete, including assets on Zcash and TRON. Both figures are legitimate readings of the same incident — one preliminary, one final — not an accounting error.
The security product became the bridge
The investigators' reconstruction is the heart of the matter. According to the security firm SlowMist, whose analysis was reported by BleepingComputer and cited by Bitget itself, the earliest malicious activity dates to 31 August, nearly a month before the theft. A service running on a node belonging to a third-party product, referred to only as "Product A," was hit by the zero-day. From there, a hidden script read the database password stored in an environment variable and connected to the database.
On 24 September (all times hereafter in Brasília time), the attacker reached the management console of a second product, "Product B," not through a new zero-day but by using the identity of an internal employee, and attempted to inject commands to write files to the server. Mandiant, Google's incident response arm, describes the next link in the chain: a web shell installed on that security appliance, a command-and-control channel opened from it and, from there, lateral movement to the server that executes withdrawals from the production wallet.
The endgame was a purpose-built tool. SlowMist says it recovered a program, later wiped by the attacker, designed around Bitget's withdrawal logic and capable of forging the parameters the risk engine checks. That tool drained the funds on the afternoon of 24 September, between 15:31 and 18:23 — just under three hours. SlowMist logs the timestamps in UTC+8, a time zone in which the theft falls in the early hours of the 25th. Neither third-party product has been named: Bitget, SlowMist and Mandiant all keep them as "A" and "B."
Why the inversion matters
Exchange heists are usually told as stories of exchange failure. Here, the first thing to fail was a security vendor, and Bitget inherited the breach by trusting it. This is supply-chain risk: an appliance that inspects traffic, sitting in the middle of the network with privileged access, becomes the ideal springboard the moment it is the thing that gets compromised.
The second detail is just as uncomfortable. The attacker did not break the withdrawal risk controls by force. He stole high-privilege internal credentials and built a tool that spoke the system's own language, presenting the withdrawals as legitimate. Risk controls only stop what they recognise as anomalous; when the request arrives signed from the inside, it goes through.
The cold wallets stayed out of it
Per Bitget's statement, the cold wallets were untouched, thanks to a three-tier architecture, and the loss is covered by a protection fund of more than $464 million. These are the exchange's own claims, not an independent audit. Bitget suspended withdrawals on 24 September and resumed them in phases: Bitcoin on 28/09, Ether on 29/09, USDT on 30/09, with the remainder expected on 2 October. It also offered a 5% bounty on anything recovered or frozen. For users, the exchange says there has been no direct loss so far, because balances remain correct and the fund absorbs the shortfall.
Of the money that walked out, little came back. Circle and Tether froze roughly $318,000 (218,023 USDT and 99,990 USDC) in a wallet that Etherscan labels "Bitget Exploiter 8," according to CoinDesk; Circle blacklisted the address at 05:00 UTC on Friday, 25 September, and Tether followed shortly after. On NEAR Intents, manager Alex Shevchenko detailed three figures, all estimates: more than $50 million in attempts blocked before the swap, roughly $503,000 frozen mid-execution and roughly $166,000 that got through. Even added together, the blocks are a tiny fraction of the theft: more than 63,000 ETH remain with the attackers, beyond the reach of any freeze, because ether cannot be frozen. The limitation is the same one we covered when Tether blocked USDT: it reaches whatever sits in a stablecoin with an identifiable issuer, not the native asset.
Attribution points to North Korea, without closing the case
The three firms that examined the trail converge, but none commits outright. Elliptic classified the attack as "highly likely" linked to North Korea, pointing to connections with addresses that laundered the $1.4 billion Bybit theft in 2025. TRM Labs was explicit that it has not yet made a definitive attribution, though it notes the same wallet overlap and an identical methodology. Bitget CEO Gracy Chen called it "very likely." That is how the word enters this story: likely, said by those doing the analysis, not as settled fact. By Elliptic's count, thefts attributed to North Korea in 2026 have already passed $1 billion.
The Brazilian angle: who covers the user here
None of this has a Brazilian guarantee equivalent. Bitget serves users in Brazil without Banco Central authorisation as a virtual asset service provider, or PSAV — which, as of 1 October, still applies to nearly the entire market: the rules took effect on 2 February and firms already operating have until 30 October to file their applications. What distinguishes a foreign exchange is not the absence of authorisation as such, but the absence of a local entity or authorised partner, and the fact that its users have nothing resembling the Fundo Garantidor de Créditos that covers bank deposits. Here, what covered the customer was the exchange's own private fund. That thread deserves an article of its own as virtual asset regulation advances in Brazil.
In one line
What breached Bitget was a third party's security product, and the lesson is not about the exchange — it is about entrusting the most privileged access on your network to a box that can also have a zero-day.
Sources
- The Hacker News — Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
- Bitget — Fund Tracing and Recovery Bounty (official statement, 25/09/2026)
- BleepingComputer — Bitget hacked via zero-day in third-party security products
- Elliptic — Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026
- TRM Labs — Bitget loses $351.6 million in hot wallet breach in likely North Korea attack
- CoinDesk — Circle and Tether step in to freeze hacker wallet after massive Bitget crypto heist
- Cointelegraph — NEAR Intents says it blocked $50M tied to Bitget hackers
- CyberX — Tether can freeze USDT. What that changes for those who lost money
About the author

Robert F.
request a secure channelRobert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.
He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.
In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.
Related reading
CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. The addresses cited are public on the blockchain. Nothing here attributes identity to whoever controls them.
how we write →Source: https://cyberx.to/en/news/the-attack-that-took-3875-million-from-bitget-came-in-through-a-security-product-not-the-exchange
Retrieved on