Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)
Bitget $387.5M Cryptocurrency Theft via Third-Party Security (TL-2026-2823), also tracked as Bitget hack, is a critical-severity supply-chain compromise, first published 2026-10-01. It is attributed to TraderTraitor (North Korea) with medium confidence, affects Unnamed third-party vendor Security product A (service on node, maps to 10 MITRE ATT&CK techniques (T1059, T1071, T1078), and is covered by 9 detection rules and 5 indicators of compromise.
Key facts for TL-2026-2823
- Threat ID
- TL-2026-2823
- Also known as
- Bitget hack, Bitget wallet infrastructure breach
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-10-01
- Last reviewed
- 2026-10-01
- Attribution
- TraderTraitor
- Attribution confidence
- MEDIUM
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- finance, cryptocurrency
- Target regions
- Global, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 5
Malware and tooling in Bitget $387.5M Cryptocurrency Theft via Third-Party Security
Malware and tooling: Avalanche, Web shell on security appliance B, Custom Bitget withdrawal tool (deleted, recovered by SlowMist)
Attackers stole about $387.5 million from Bitget hot and warm wallets on 24-25 September 2026 after exploiting a zero-day in an unnamed third-party security product (Product A) and compromising a second one (Product B), then using a custom withdrawal tool. Bitget attributes the intrusion to North Korean actors based on IP behavior and on-chain analysis; Mandiant and SlowMist are investigating.
How Bitget $387.5M Cryptocurrency Theft via Third-Party Security works
Bitget disclosed unauthorized transfers from its hot and warm wallets on 24 September 2026 (18:31 UTC; 02:31 on 25 September UTC+8). Initial estimates of $351.6M were revised to $387.5M after further ZEC and TRX losses were found. Bitget says private keys and cold wallets were not compromised and the exchange's User Protection Fund (reported above $464M) covers losses.
Per the interim SlowMist and Mandiant findings reported on 30 September 2026, the earliest malicious activity was on 31 August 2026 against 'Product A', an unnamed third-party security product, through a zero-day in a service running on a node. The attacker ran hidden scripts under that service process, read an environment variable holding the database password, and connected directly to the database. Similar hidden-script activity appeared on further nodes between 23 and 25 September.
On 24 September (about 16:07 UTC) the attacker moved into 'Product B', a security management platform, reportedly using an internal employee identity. SlowMist reports three consecutive system command injection attempts into task parameters, use of a web execution endpoint, relay communication files written to the server, and batch assembly and upload of malicious programs (first activity about 17:49 UTC). Mandiant found a web shell on security appliance B that established a command-and-control connection and allowed lateral movement to Bitget's production wallet job server, where malicious packages were deployed.
SlowMist recovered a deleted, highly customized tool built around the wallet system's withdrawal logic. It forged risk-control parameters, built withdrawal requests and invoked withdrawals, spoofing transaction data to trigger the exchange's normal authorization signing process. Theft ran in waves across 11 chains (Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, Celestia), with the largest wave of about $185M reported in roughly one minute around 19:16 UTC. The on-chain window closed around 21:23 UTC. Failed BTC withdrawal attempts and attempted log alterations were also observed.
Attribution to North Korean actors rests on IP behavior patterns and on-chain analysis. Elliptic and TRM Labs report wallet overlaps with earlier DPRK-attributed hacks, and Elliptic ties the laundering pattern to TraderTraitor. Funds were swapped within hours and routed through cross-chain venues including THORChain and Chainflip; Bitget asked THORChain to refuse service to attacker addresses, and about $632,700 was frozen by Circle, Tether and NEAR Intents. No government attribution has been issued. No CVE, vendor/product names, hashes, IPs, domains or wallet addresses had been published at the time of research.
MITRE ATT&CK techniques used in TL-2026-2823
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise
Persistence
T1505.003 Server Software Component: Web Shell
Credential Access
Impact
T1565.002 Data Manipulation: Transmitted Data Manipulation; T1657 Financial Theft
Lateral Movement
Affected products and versions in Bitget $387.5M Cryptocurrency Theft via Third-Party Security
- Unnamed third-party vendor — Security product A (service on node; zero-day)
Vulnerable versions: unknown - Unnamed third-party vendor — Security management platform B (appliance with web shell)
Vulnerable versions: unknown - Bitget — Centralized exchange hot and warm wallet infrastructure
Vulnerable versions: not applicable
Remediation for Bitget $387.5M Cryptocurrency Theft via Third-Party Security
Patches
- Vendor patches for the unnamed third-party products were pending at time of reporting; apply them when released
Immediate actions
- Hunt for hidden scripts spawned under security-appliance service processes and for reads of service environment variables that hold database credentials
- Review security-appliance management platforms for command injection into task parameters, unexpected web-execution endpoint use and relay files written to disk
- Audit use of employee identities against security management platforms and rotate those credentials
- Treat withdrawal/signing pipelines as untrusted if the upstream risk-control or job server was reachable from a compromised appliance
Workarounds
- Disable the affected third-party functionality until fixes ship (the step Bitget took)
Longer-term hardening
- Segment security appliances and their management planes from wallet job servers and signing infrastructure
- Add independent, out-of-band validation of withdrawal requests and risk-control parameters
- Keep cold wallets and private keys isolated from application-layer backends
Weaknesses (CWE) in Bitget $387.5M Cryptocurrency Theft via Third-Party Security
CWE-78
Timeline of Bitget $387.5M Cryptocurrency Theft via Third-Party Security
- Earliest malicious activity: zero-day in a service on a node of third-party security Product A exploited; hidden script reads the database password from an environment variable
- Hidden-script activity begins appearing on additional nodes (observed through 25 September)
- On-chain theft window closes around 21:23 UTC; failed BTC withdrawal attempts and log alteration attempts observed; Bitget suspends withdrawals and discloses the breach
- 18:31 UTC (02:31 on 25 Sep UTC+8): first on-chain outflows from hot and warm wallets via the custom withdrawal tool; largest wave about $185M in roughly one minute near 19:16 UTC
- Around 16:07 UTC the attacker moves into security management platform Product B using an internal employee identity and attempts three command injections into task parameters; malicious programs start about 17:49 UTC
- Bitget attributes the attack to suspected North Korean actors based on IP behavior and on-chain analysis; initial loss estimate $351.6M; Elliptic and TRM Labs report wallet overlaps with prior DPRK hacks
- Losses revised to $387.5M after additional ZEC and TRX theft is found; Bitget asks THORChain to refuse service to attacker addresses
- SlowMist and Mandiant publish interim findings: two third-party security products compromised, web shell with C2 on appliance B, lateral movement to the production wallet job server
- Bitget confirms the third-party zero-day vector, notifies the vendor and disables affected functionality pending fixes; about $632,700 frozen by Circle, Tether and NEAR Intents
Sources cited for Bitget $387.5M Cryptocurrency Theft via Third-Party Security
- Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
- Bitget Says Suspected North Korean Actors Behind Cryptocurrency Theft
- Bitget hacked via zero-day in third-party security products
- SlowMist Traces Bitget Hack Activity to Zero-Day Exploit
- Bitget $387.5M Hack: SlowMist and Mandiant Say Zero-Day Attack Began Weeks Before Theft
- Bitget blames North Korea for $387.5M crypto wallet raid
- Bitget Raises Hack Losses to $387.5M After New ZEC and TRX Findings
- Bitget formally asks THORChain to refuse service to attacker addresses
More in supply chain
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini Shai-Hulud CI/CD Credential-Theft Payload
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)
Detection coverage for TL-2026-2823
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2823 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.