Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)

Bitget $387.5M Cryptocurrency Theft via Third-Party Security (TL-2026-2823), also tracked as Bitget hack, is a critical-severity supply-chain compromise, first published 2026-10-01. It is attributed to TraderTraitor (North Korea) with medium confidence, affects Unnamed third-party vendor Security product A (service on node, maps to 10 MITRE ATT&CK techniques (T1059, T1071, T1078), and is covered by 9 detection rules and 5 indicators of compromise.

Key facts for TL-2026-2823

Threat ID
TL-2026-2823
Also known as
Bitget hack, Bitget wallet infrastructure breach
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
2026-10-01
Last reviewed
2026-10-01
Attribution
TraderTraitor
Attribution confidence
MEDIUM
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
finance, cryptocurrency
Target regions
Global, Asia-Pacific
Detection rules
9
Indicators of compromise
5

Malware and tooling in Bitget $387.5M Cryptocurrency Theft via Third-Party Security

Malware and tooling: Avalanche, Web shell on security appliance B, Custom Bitget withdrawal tool (deleted, recovered by SlowMist)

Attackers stole about $387.5 million from Bitget hot and warm wallets on 24-25 September 2026 after exploiting a zero-day in an unnamed third-party security product (Product A) and compromising a second one (Product B), then using a custom withdrawal tool. Bitget attributes the intrusion to North Korean actors based on IP behavior and on-chain analysis; Mandiant and SlowMist are investigating.

How Bitget $387.5M Cryptocurrency Theft via Third-Party Security works

Bitget disclosed unauthorized transfers from its hot and warm wallets on 24 September 2026 (18:31 UTC; 02:31 on 25 September UTC+8). Initial estimates of $351.6M were revised to $387.5M after further ZEC and TRX losses were found. Bitget says private keys and cold wallets were not compromised and the exchange's User Protection Fund (reported above $464M) covers losses.

Per the interim SlowMist and Mandiant findings reported on 30 September 2026, the earliest malicious activity was on 31 August 2026 against 'Product A', an unnamed third-party security product, through a zero-day in a service running on a node. The attacker ran hidden scripts under that service process, read an environment variable holding the database password, and connected directly to the database. Similar hidden-script activity appeared on further nodes between 23 and 25 September.

On 24 September (about 16:07 UTC) the attacker moved into 'Product B', a security management platform, reportedly using an internal employee identity. SlowMist reports three consecutive system command injection attempts into task parameters, use of a web execution endpoint, relay communication files written to the server, and batch assembly and upload of malicious programs (first activity about 17:49 UTC). Mandiant found a web shell on security appliance B that established a command-and-control connection and allowed lateral movement to Bitget's production wallet job server, where malicious packages were deployed.

SlowMist recovered a deleted, highly customized tool built around the wallet system's withdrawal logic. It forged risk-control parameters, built withdrawal requests and invoked withdrawals, spoofing transaction data to trigger the exchange's normal authorization signing process. Theft ran in waves across 11 chains (Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, Celestia), with the largest wave of about $185M reported in roughly one minute around 19:16 UTC. The on-chain window closed around 21:23 UTC. Failed BTC withdrawal attempts and attempted log alterations were also observed.

Attribution to North Korean actors rests on IP behavior patterns and on-chain analysis. Elliptic and TRM Labs report wallet overlaps with earlier DPRK-attributed hacks, and Elliptic ties the laundering pattern to TraderTraitor. Funds were swapped within hours and routed through cross-chain venues including THORChain and Chainflip; Bitget asked THORChain to refuse service to attacker addresses, and about $632,700 was frozen by Circle, Tether and NEAR Intents. No government attribution has been issued. No CVE, vendor/product names, hashes, IPs, domains or wallet addresses had been published at the time of research.

MITRE ATT&CK techniques used in TL-2026-2823

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise

Persistence

T1505.003 Server Software Component: Web Shell

Credential Access

T1552 Unsecured Credentials

Impact

T1565.002 Data Manipulation: Transmitted Data Manipulation; T1657 Financial Theft

Lateral Movement

T1570 Lateral Tool Transfer

Affected products and versions in Bitget $387.5M Cryptocurrency Theft via Third-Party Security

  • Unnamed third-party vendor — Security product A (service on node; zero-day)
    Vulnerable versions: unknown
  • Unnamed third-party vendor — Security management platform B (appliance with web shell)
    Vulnerable versions: unknown
  • Bitget — Centralized exchange hot and warm wallet infrastructure
    Vulnerable versions: not applicable

Remediation for Bitget $387.5M Cryptocurrency Theft via Third-Party Security

Patches

  • Vendor patches for the unnamed third-party products were pending at time of reporting; apply them when released

Immediate actions

  • Hunt for hidden scripts spawned under security-appliance service processes and for reads of service environment variables that hold database credentials
  • Review security-appliance management platforms for command injection into task parameters, unexpected web-execution endpoint use and relay files written to disk
  • Audit use of employee identities against security management platforms and rotate those credentials
  • Treat withdrawal/signing pipelines as untrusted if the upstream risk-control or job server was reachable from a compromised appliance

Workarounds

  • Disable the affected third-party functionality until fixes ship (the step Bitget took)

Longer-term hardening

  • Segment security appliances and their management planes from wallet job servers and signing infrastructure
  • Add independent, out-of-band validation of withdrawal requests and risk-control parameters
  • Keep cold wallets and private keys isolated from application-layer backends

Weaknesses (CWE) in Bitget $387.5M Cryptocurrency Theft via Third-Party Security

CWE-78

Timeline of Bitget $387.5M Cryptocurrency Theft via Third-Party Security

  • Earliest malicious activity: zero-day in a service on a node of third-party security Product A exploited; hidden script reads the database password from an environment variable
  • Hidden-script activity begins appearing on additional nodes (observed through 25 September)
  • On-chain theft window closes around 21:23 UTC; failed BTC withdrawal attempts and log alteration attempts observed; Bitget suspends withdrawals and discloses the breach
  • 18:31 UTC (02:31 on 25 Sep UTC+8): first on-chain outflows from hot and warm wallets via the custom withdrawal tool; largest wave about $185M in roughly one minute near 19:16 UTC
  • Around 16:07 UTC the attacker moves into security management platform Product B using an internal employee identity and attempts three command injections into task parameters; malicious programs start about 17:49 UTC
  • Bitget attributes the attack to suspected North Korean actors based on IP behavior and on-chain analysis; initial loss estimate $351.6M; Elliptic and TRM Labs report wallet overlaps with prior DPRK hacks
  • Losses revised to $387.5M after additional ZEC and TRX theft is found; Bitget asks THORChain to refuse service to attacker addresses
  • SlowMist and Mandiant publish interim findings: two third-party security products compromised, web shell with C2 on appliance B, lateral movement to the production wallet job server
  • Bitget confirms the third-party zero-day vector, notifies the vendor and disables affected functionality pending fixes; about $632,700 frozen by Circle, Tether and NEAR Intents

Sources cited for Bitget $387.5M Cryptocurrency Theft via Third-Party Security

More in supply chain

Detection coverage for TL-2026-2823

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2823 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats