<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/bitget-hacked-via-zero-day-in-third-party-security-products-tiafv2oyn" -->

---
title: Bitget hacked via zero-day in third-party security products
description: Bitget disclosed that the $387.5 million theft from its hot and warm wallets last week resulted from attackers exploiting a zero-day vulnerability in two...
canonical: https://daily.dev/posts/bitget-hacked-via-zero-day-in-third-party-security-products-tiafv2oyn
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Bitget hacked via zero-day in third-party security products | daily.dev
og:description: Bitget disclosed that the $387.5 million theft from its hot and warm wallets last week resulted from attackers exploiting a zero-day vulnerability in two...
og:url: https://daily.dev/posts/bitget-hacked-via-zero-day-in-third-party-security-products-tiafv2oyn
og:image: https://api.daily.dev/og/posts/TIAfv2oYN.png
og:image:alt: Bitget hacked via zero-day in third-party security products
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Bitget hacked via zero-day in third-party security products

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Bitget disclosed that the $387.5 million theft from its hot and warm wallets last week resulted from attackers exploiting a zero-day vulnerability in two third-party security appliances. Investigations by SlowMist and Mandiant found the attacker had unauthorized access as early as August 31, deployed a web shell on one appliance, established C2 access, and moved laterally to Bitget's production wallet job server, deploying malware and a custom withdrawal tool used to execute the theft after midnight on September 25. CEO Gracy Chen attributed the attack to North Korean hackers based on IP patterns and on-chain analysis. Bitget has launched a Recovery Bounty Program offering 5% bounties for help recovering or freezing the stolen funds.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products>

## Questions this post answers

### How did attackers steal $387.5 million from Bitget?

Attackers exploited a zero-day vulnerability in two third-party security appliances used by Bitget, deploying a web shell and establishing command-and-control access on one appliance, then moving laterally to the exchange's production wallet job server. They deployed malware and a custom withdrawal tool that spoofed transaction data to trigger fund authorization, stealing funds across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base after midnight on September 25.

_Security teams tracking supply-chain risks from third-party appliances can follow incident writeups like this on daily.dev._

### When did the malicious activity in the Bitget hack begin?

The earliest identified malicious activity dates to August 31, when a service on one of the compromised security appliance's nodes was affected by a zero-day vulnerability, allowing an attacker to run a hidden script that read the database password from an environment variable and connect to the database. Similar hidden-script activity was later observed on other nodes on September 23 and 25.

_Anyone investigating exchange breach timelines can keep up with forensic details like these on daily.dev._

## Similar posts on daily.dev

- [Bitget blames North Korea for $387.5M crypto wallet raid](https://daily.dev/posts/bitget-blames-north-korea-for-387-5m-crypto-wallet-raid-ep7zcbwic) · The Register · 1 upvotes · 0 comments
- [The $1.5B Blind Spot — And Why You’re Next](https://daily.dev/posts/the-1-5b-blind-spot-and-why-you-re-next-4zf39eghr) · Coins Bench · 7 upvotes · 0 comments
- [Lazarus Group Bitrefill Cyberattack Crypto Threat](https://daily.dev/posts/lazarus-group-bitrefill-cyberattack-crypto-threat-vztjwi1no) · Cyble · 0 upvotes · 0 comments
- [Trust Wallet Chrome Extension Breach Caused $7 Million Crypto Loss via Malicious Code](https://daily.dev/posts/trust-wallet-chrome-extension-breach-caused-7-million-crypto-loss-via-malicious-code-ithogpjly) · The Hacker News · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/bitget-hacked-via-zero-day-in-third-party-security-products-tiafv2oyn)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Bitget hacked via zero-day in third-party security products","url":"https://daily.dev/posts/bitget-hacked-via-zero-day-in-third-party-security-products-tiafv2oyn","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/bitget-hacked-via-zero-day-in-third-party-security-products-tiafv2oyn"},"datePublished":"2026-09-30T11:12:32.700Z","dateModified":"2026-09-30T11:33:24.000Z","description":"Bitget disclosed that the $387.5 million theft from its hot and warm wallets last week resulted from attackers exploiting a zero-day vulnerability in two...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5b5d6d12bd625e934536caa6a0dc4c6f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5b5d6d12bd625e934536caa6a0dc4c6f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/bitget-hacked-via-zero-day-in-third-party-security-products-tiafv2oyn","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,zero-day","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Bitget hacked via zero-day in third-party security products"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/bitget-hacked-via-zero-day-in-third-party-security-products-tiafv2oyn#faq","mainEntity":[{"@type":"Question","name":"How did attackers steal $387.5 million from Bitget?","acceptedAnswer":{"@type":"Answer","text":"Attackers exploited a zero-day vulnerability in two third-party security appliances used by Bitget, deploying a web shell and establishing command-and-control access on one appliance, then moving laterally to the exchange's production wallet job server. They deployed malware and a custom withdrawal tool that spoofed transaction data to trigger fund authorization, stealing funds across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base after midnight on September 25. Security teams tracking supply-chain risks from third-party appliances can follow incident writeups like this on daily.dev."}},{"@type":"Question","name":"When did the malicious activity in the Bitget hack begin?","acceptedAnswer":{"@type":"Answer","text":"The earliest identified malicious activity dates to August 31, when a service on one of the compromised security appliance's nodes was affected by a zero-day vulnerability, allowing an attacker to run a hidden script that read the database password from an environment variable and connect to the database. Similar hidden-script activity was later observed on other nodes on September 23 and 25. Anyone investigating exchange breach timelines can keep up with forensic details like these on daily.dev."}}]}
```

