
SlowMist links the $387.5 million Bitget hack to a third-party zero-day exploit. Here’s how attackers targeted the exchange’s wallets.
Author: Kritika Gupta
30th September 2026 – SlowMist and Mandiant say the Bitget hack ran through a third-party security product, not a stolen key.
High Signal Summary For A Quick Glance
Bonjour_fren
@Bonjour_fren
@leeky_k_crypt Exploiting a zero-day in an external security vendor to forge internal employee credentials exposes how supply-chain dependencies can completely bypass core wallet risk controls.
BREAKING: SLOWMIST SAYS BITGET HACK INVOLVED THIRD-PARTY ZERO-DAY SlowMist says its investigation found the Bitget hot wallet theft involved exploitation of a zero-day vulnerability in a third-party product. The attacker also accessed that product's management platform using an https://t.co/nU8gCO1CDK https://t.co/W44SMZPr18
07:55 AM·Sep 30, 2026
Tal Be'ery
@TalBeerySec
@SlowMist_Team @bitget Interesting, thank for sharing. Will there be more details, as the investigation continues and / or vulns are patched? In addition, could you specify whether the third-party security solutions are generic or crypto-specific?
@bitget has engaged SlowMist’s security team to investigate the September 25 hot wallet asset theft. As of September 29, our investigation has identified malicious activity involving certain third-party security products and a wallet application host, as well as a highly https://t.co/JQ3zoAH5Yi
06:01 AM·Sep 30, 2026
Westivon
@Westivon
@SlowMist_Team @bitget Nearly 3 hours of cross-chain activity followed by attempts to manipulate withdrawal records. The big security question now is how the attacker moved laterally between the affected systems—and where that movement could have been stopped earlier.
@bitget has engaged SlowMist’s security team to investigate the September 25 hot wallet asset theft. As of September 29, our investigation has identified malicious activity involving certain third-party security products and a wallet application host, as well as a highly https://t.co/JQ3zoAH5Yi
04:16 AM·Sep 30, 2026
High attention and emotional sentiment detected.
The forensic notes landed on Tuesday, six days after attackers drained roughly $387.5 million from Bitget’s hot and warm wallets. According to both firms, the attacker never touched a private key. Instead, they poisoned the software that tells those keys what to sign.
The first unauthorized transfers hit at 18:31 UTC on September 24. That clock reads 02:31 on September 25 in Bitget’s local time. So the two dates online describe one incident, split only by time zone.
The attacker started small. Two tiny test sends slipped under Bitget’s risk thresholds and raised no alarm. Each moved only a fraction of an ETH and a handful of TRX. Then, about 30 minutes later, the large waves began.
Funds left on eight chains within seconds. Bitget’s reconciliation system finally flagged a discrepancy around 19:05 UTC, and the exchange blocked user withdrawals shortly after. In total, the on-chain drain ran about two hours and 52 minutes, according to SlowMist.
Picture an exchange wallet as three rooms. Cold storage keeps keys offline, and it stayed shut. Hot and warm wallets keep keys online so the exchange can pay withdrawals. The third room holds the software that decides what those keys sign.
Bitget says room three got poisoned while the keys stayed put. As a result, the exchange’s own signers approved payments to attacker addresses because every request looked legitimate.
Gracy Chen, Bitget’s CEO, put it plainly. “The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she told CoinDesk. She added that Bitget has ruled out any private key compromise.
SlowMist, the Chinese blockchain security firm that Bitget hired, published its summary at 04:01 UTC on September 30. The firm traced malicious activity on a third-party security product through a zero-day, meaning a flaw with no existing patch.
From there, the attacker reached a vendor management platform using an internal employee identity. Next, they moved laterally onto the wallet application host, the machine that builds withdrawal jobs. Finally, they deployed a highly customized withdrawal tool built to speak Bitget’s real withdrawal logic.
Mandiant, the Google Cloud unit working the case alongside SlowMist, reached a matching conclusion. Its analysts found persistent access through security appliances, then movement onto production wallet servers, and finally malware. Crucially, Mandiant reported no evidence of private key leakage and confirmed cold wallets were safe.
SlowMist also flagged a later twist. After the drain, the attacker tried to edit withdrawal records to queue additional Bitcoin withdrawals. In other words, they still had a hand on the bookkeeping layer, not just one signed transaction.
Bitget hack: theft, investigation and disclosure
Bitget detects unauthorized wallet transfers and pauses withdrawals. The incident begins on September 24 in UTC.
Bitget engages SlowMist and Mandiant, publishes attacker addresses and begins reopening withdrawals in phases.
The investigation documents malicious activity involving third-party security products and wallet application hosts.
SlowMist publishes findings linking the breach to a third-party zero-day vulnerability and a customized withdrawal tool.
Further disclosures may clarify the complete attack path, fund recovery and how Bitget covers the losses.
The stolen assets spanned XRP, ETH, USDT, ZEC, USDC, BNB, AVAX, TRX and more. The single largest slice was about 103 million XRP, worth roughly $157 million at the time. Bitget’s first count came to $351.6 million, then rose to $387.5 million once the Zcash and TRON legs were added.
An independent tally from Bitquery logged 21 transfers across eight chains, worth about $357.36 million by transfer-hour prices. The gap between the numbers comes down to valuation timing and how each side classified ZEC and TRX.
Laundering started quickly. The attacker swapped stablecoins into ETH within minutes. Then they routed XRP toward Bitcoin through bridges like THORChain and Chainflip. Meanwhile, Circle, Tether and NEAR Intents froze small slices, though the frozen total stays tiny next to the full haul. Bitget has not published any recovered-funds figure.
Bitget paused withdrawals during the drain, then reopened them in stages. Bitcoin came back on September 28, Ether on September 29, and USDT on September 30. The rest follows on October 2. The exchange says customer ledger balances stayed intact and its User Protection Fund absorbed the loss.
Still, users voted with their wallets. Bloomberg, citing DefiLlama proof-of-reserves data, reported roughly $463 million in net customer outflows in the 24 hours into September 29. That marks the largest single-day net outflow in DefiLlama’s four-year series. Even so, Bitget’s reserves still sat near $5.7 billion.
The token told a quieter story. BGB traded near $2.04 before the Bitget hack. By September 30 it hovered around $1.99, down roughly 6% on the week. The cleanest market fingerprint was volume, which spiked to about $43 million on September 25.
Several investigators lean toward North Korea, yet nobody has proven it. Chen first called the method “highly consistent with known patterns of North Korean hacker organisations.” She cited IP behavior and on-chain analysis. Later, though, she told Cointelegraph the indicators are “preliminary” and “still being assessed.”
TRM Labs described the attack as a “likely” North Korea operation. Independent tracers linked some XRP hops to clusters tied to past Lazarus activity. Yet no FBI, DOJ or United Nations body has confirmed attribution. So this stays a pattern match, not a government indictment.
One more gap matters. Chen has declined to name the third-party vendor until the formal incident report drops. As she told Dow Jones, Bitget no longer uses the product and is working with the vendor on a fix.
For now, the Bitget hack sits in its forensic chapter. The money story peaked in the first 48 hours, and the technical story is still being written. Key questions stay open. Those include the vendor name, the final recoverable amount, and the true cost to the protection fund.
Watch three things from here. First, whether Bitget publishes the promised full report and names the appliance. Second, whether outflows keep climbing or stabilize as the last assets reopen. Third, whether any government confirms attribution. Until then, treat the North Korea angle and the recovery outlook as unsettled. This is not financial advice.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
Bitget Hack & SlowMist Probes Supply-Chain Vector
NEAR Intents Says SHIELD Blocked $50M in Bitget Funds
ZachXBT Exposes Bitget Hack Laundering in Discords
KelpDAO LayerZero Lawsuit Targets CEO Over $292M Hack
Bitget Hack & SlowMist Probes Supply-Chain Vector
NEAR Intents Says SHIELD Blocked $50M in Bitget Funds
ZachXBT Exposes Bitget Hack Laundering in Discords
KelpDAO LayerZero Lawsuit Targets CEO Over $292M Hack