Cryptocurrency exchange Bitget has confirmed that the attackers behind a $387.5 million theft disclosed last week exploited a zero-day vulnerability in third-party security products to breach its wallet infrastructure. The confirmation follows parallel investigations by blockchain security firm SlowMist and Google Cloud’s Mandiant.

According to the findings, the earliest malicious activity traces back to August 31, when a service running on one of two compromised security appliances, referred to as Product A, was affected by the zero-day. The attacker ran a hidden script under the service process to read an environment variable containing a database password, then connected to the database directly. Similar hidden-script activity was later observed on additional nodes on September 23 and 25.

Mandiant’s forensic review found that on September 24, 2026, the threat actor gained unauthorized privileged access to two of Bitget’s third-party security appliances. A web shell was deployed on one appliance, establishing a command-and-control connection that the attacker used to move laterally into Bitget’s production wallet job server, where malicious packages and a custom withdrawal tool were installed.

Theft Spanned Multiple Chains in Under Three Hours

SlowMist pinpointed the first fraudulent transfer at 02:31 (UTC+8) on the night of the attack, with the last occurring at 05:23, a window of nearly three hours across multiple blockchains. Bitget suspended withdrawals after detecting unauthorized movements from its hot and warm wallets.

CEO Gracy Chen said the stolen assets included ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens, spread across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base networks. Chen attributed the attack to North Korean state-linked hackers, citing IP behavior patterns and on-chain analysis, and said the group compromised a critical backend system within the wallet infrastructure that was used to spoof transaction data and trigger the exchange’s authorization process.

Response and Recovery

North Korean-linked actors have been tied to several major exchange heists, including the $1.5 billion theft from Bybit’s cold wallet. Bitget has since launched a Recovery Bounty Program offering 5% rewards to anyone who helps recover or freeze the stolen funds. The exchange has not yet disclosed the identity of the third-party security vendor or the specific zero-day exploited.