← All posts

Security

Bitget's Root-Cause Report Says the Attackers Came In Through Its Security Products. The Appliance That Watches Everything Can Also Reach Everything

Bitget published its breach findings on September 30: a zero-day in a third-party security appliance gave attackers a foothold on August 31, three and a half weeks before $387.5 million left its wallets. The defensive control was not bypassed — it was the route in.

MAI
Bitget's official brand graphic: the Bitget wordmark and logo on a plain dark background, used by the exchange as the preview image for its own site.

Bitget published the findings of its breach investigation on September 30, six days after roughly $388 million left its hot and warm wallets. On the night of the theft the exchange ruled out a stolen private key and said a backend component had been compromised, without saying which. That gap is now filled, and the answer is the uncomfortable one: the attackers came in through the security products.

What the report says

A status update prepared by Mandiant and hosted on Bitget's own domain, together with findings from blockchain security firm SlowMist, describes an intrusion that began on August 31 — roughly three and a half weeks before any money moved.

DateEvent
August 31Earliest malicious activity on the first third-party security appliance
September 23–25Activity observed on additional nodes
September 24 (UTC)Attacker reaches the second appliance's management platform using employee credentials
September 24, 18:31 UTCUnauthorized transfers begin; roughly three hours of outflows
September 26Withdrawals suspended
September 30Root-cause findings published

The loss has been revised upward to $387.5 million, from the $351.6 million Bitget gave in the first hours. Assets moved across Ethereum, the XRP Ledger, BNB Smart Chain, Arbitrum, Optimism, Base, Avalanche, TRON, Zcash, Algorand and Celestia. Cold wallets, private keys and the self-custodial Bitget Wallet were not affected.

The mechanism Bitget describes is a chain of privilege rather than a single bug. A zero-day in a third-party security product gave the attackers a foothold; from there they reached the data store behind it, and then the management platform of a second appliance using employee credentials. CEO Gracy Chen's summary is that the flaw let the attacker obtain "high-level internal credentials" — enough to issue withdrawal instructions the wallet infrastructure treated as legitimate, including forged risk-control parameters. Neither vendor has been named. Bitget says it notified the vendor and disabled the affected functionality pending a fix. No CVE has been published.

The appliance that watches everything can reach everything

This is the part that generalises past crypto. A security appliance earns its position by being privileged: it inspects traffic the rest of the network cannot, holds credentials for the systems it protects, and sits in the management plane rather than beside it. Those properties are the product. They are also what makes a zero-day in one worth more than a zero-day in almost anything else it is guarding.

The industry has spent two years learning this at the network edge — Ivanti, Fortinet, SonicWall, Citrix NetScaler last weekend, F5 the week before. Bitget is the same lesson arriving one layer in. The defensive control was not bypassed; it was the route. An organisation that had hardened its wallet infrastructure and left its security stack to the vendor would have ended up exactly here.

The dwell time is the other number worth holding onto. Three and a half weeks passed between the first malicious activity and the transfers. That is not a smash-and-grab; it is the interval in which an attacker learns an unfamiliar wallet pipeline well enough to produce instructions it will accept. Detection had three and a half weeks and did not fire, in part because the thing behaving strangely was the thing that watches for strange behaviour.

Recovery is effectively over

Published figures for frozen assets range from roughly $633,000 to $1.1 million, through Circle, Tether and NEAR Intents. Against $387.5 million, that is a rounding error. Chen has said she is "not very optimistic" about recovery, citing how little came back from Bybit's $1.5 billion loss in 2025.

Attribution points to North Korea, now with more behind it than the exchange's own reading of IP patterns: Elliptic and TRM Labs have reported wallet overlaps linking the proceeds to earlier thefts. Customers are covered either way — Bitget's protection fund exceeds the loss — so the money question was never solvency. It was whether anyone would learn something transferable.

What this asks of everyone else

The question every custodian should have asked a week ago was whether a compromised internal service could cause a valid signature over an invalid transaction. Bitget's report narrows it. The service that gets compromised may be the one you bought to prevent that, it may be compromised through a flaw its vendor does not know about, and it may sit inside your environment for a month before anything visible happens.

That does not argue against buying security products. It argues for treating them as what they are — privileged software with ordinary bugs, deserving the same network segmentation, credential scoping, egress control and independent monitoring applied to anything else that can reach production. An appliance exempted from scrutiny because it is the thing doing the scrutinising is the best-placed asset in the building.

Sources: Mandiant status update hosted by Bitget (PDF) · BleepingComputer — Bitget hacked via zero-day in third-party security products · The Hacker News — Bitget confirms third-party zero-day behind $387.5 million cryptocurrency theft · Cointelegraph — SlowMist traces Bitget hack activity to zero-day exploit · TechNadu — Bitget confirms zero-day behind $387.5M crypto theft

Keep reading