Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-01 · updated: 2026-10-01 · tags: [incident, financial-services, zero-day] · confidence: high · severity: high · affected_sectors: [financial-services] · au_impact: false

Two independent investigations — by blockchain security firm SlowMist and Google Cloud's Mandiant — found that the attackers who drained US$387.5 million from the Bitget exchange's hot and warm wallets reached the wallet environment by compromising two third-party security appliances with zero-day exploits. SlowMist dates the earliest malicious activity to 31 August, when a hidden script on one appliance node read an environment variable containing the database password and connected to the database, with similar activity on two further nodes on 23 and 25 September. Mandiant says the actor gained privileged access to both appliances on 24 September, dropped a web shell on one and established command-and-control, then moved laterally to the production wallet job server and deployed malicious packages plus a custom withdrawal tool. Theft transfers ran across roughly three hours on multiple chains — Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base — spanning ETH, XRP, BNB, AVAX, USDT and USDC. Bitget's CEO blamed North Korean actors on IP and on-chain evidence; the vendor has launched a 5% recovery bounty. Neither third-party appliance vendor nor the CVEs have been named publicly.

Attribute Detail
Sector Financial Services
Date 2026-10-01
Source BleepingComputer
Reliability Tier 2