Markets
BTC$83,826+0.41%ETH$2,676−0.61%SOL$117.94−0.85%XRP$1.49−0.04%BNB$767.12+1.69%DOGE$0.0943+0.58%ADA$0.2433−0.41%TRX$0.3380+0.87%LINK$14.30−2.33%AVAX$10.93−3.61%SUI$1.16+0.64%HYPE$89.37+4.11%
USD · 24h
Wednesday, September 30, 2026Crypto markets, policy & blockchain
Digital Coin Journal
Security

Bitget Hack Began Weeks Before $387.5M Theft

SlowMist traces the $387.5M Bitget breach to an Aug. 31 intrusion exploiting third-party security products before fraudulent withdrawals began.

Data center rack with two security appliances labeled Product A and B, a shadowy hacker nearby, and digital code trails.

The attacker behind Bitget’s roughly $387.5 million security breach had established a foothold in third-party infrastructure weeks before funds began leaving the exchange, according to new forensic findings from SlowMist and Mandiant. The earliest malicious activity identified so far dates to August 31, nearly four weeks before the September 24 wallet drain. Bitget says the incident ultimately affected hot and warm wallets while leaving private keys and cold storage uncompromised.

According to SlowMist’s interim Bitget investigation report, a service running on what investigators call “Product A” was affected by a zero-day vulnerability. The attacker ran a concealed script that attempted to retrieve a database password from an environment variable and connect to the database. Similar hidden-script activity appeared on additional nodes on September 23 and September 25, indicating that parts of the environment had been compromised before the asset transfers began.

Third-Party Appliances Opened a Path to Wallet Systems

Mandiant’s separate incident response status report says the threat actor obtained unauthorized privileged access to two third-party security appliances, labeled A and B, on September 24. A web shell was deployed on appliance B and used to establish command-and-control access before the attacker moved laterally into Bitget’s production wallet job server. The breach therefore occurred through security infrastructure surrounding the wallet environment rather than through theft of Bitget’s private keys.

SlowMist’s findings add that an internal employee identity was used to enter Product B’s management platform, where the attacker attempted command injection, configuration changes and malicious-file deployment. Investigators also recovered a highly customized tool built around Bitget’s withdrawal logic. The attacker appears to have converted legitimate administrative access paths into a mechanism for creating withdrawal instructions that the backend accepted as authorized. Similar supply-chain risks have appeared elsewhere in crypto infrastructure, including a compromised Injective SDK designed to steal wallet credentials.

Bitget’s own incident report says stolen high-privilege credentials were used to write forged withdrawal commands directly into wallet-related backend servers, bypassing normal risk checks. Unauthorized transfers then ran across multiple blockchains for almost three hours, beginning at 02:31 UTC+8 on September 25. Approximately $387.5 million was ultimately transferred to attacker-controlled addresses across Ethereum and other EVM networks, XRP Ledger, Zcash and TRON.

Failed Bitcoin Withdrawals Reveal Continued Access

The attacker did not stop after the main outbound transfers. SlowMist reported attempts to modify withdrawal records directly inside the wallet database and trigger additional Bitcoin withdrawals locally. Two fabricated BTC withdrawal orders entered processing but failed with errors, after which the attacker reviewed logs and order status information before trying again. Those actions suggest the threat actor retained interactive access to the withdrawal environment even after the principal theft sequence had begun.

The incident reinforces the distinction between blockchain-layer exploits and compromises of operational infrastructure. A smart contract can remain secure while administrative systems, vendor appliances or wallet orchestration software become the actual attack boundary, just as a recent Balancer incident was traced to application-level logic rather than the underlying blockchain. In Bitget’s case, the available evidence points to compromised security products and internal wallet-control systems, not a failure of Ethereum, XRP Ledger or the other affected networks.

Bitget says it has patched the vulnerability, reset internal credentials, tightened sensitive permissions and strengthened independent withdrawal verification. The exchange is also relying on its Protection Fund to absorb the financial impact, a response that highlights broader coverage and loss-absorption challenges after major crypto hacks. The next concrete milestone is the full forensic report from SlowMist and Mandiant, particularly whether it establishes the complete lateral-movement path between the third-party appliances and Bitget’s wallet infrastructure.

Derek Vaughn

Hi! I'm Derek Vaughn, a Market Research Specialist based in Nigeria. I analyze crypto markets from a global perspective, trying to understand what's behind price movements and liquidity trends. I've been covering the digital ecosystem for several years, and my style is based on rigorous, data-driven research.

More from Derek Vaughn →

This article is for information only and is not investment advice. We report under our Editorial Policy; to flag an error, see our Corrections Policy.