Skip to content

Bitget blames $387M crypto theft on zero-days in security appliances

Bitget says attackers stole roughly $387M by exploiting zero-days in two third-party security appliances, then spoofed its payout authorization; the exchange suspects North Korea.

Published 3 min read

Cryptocurrency exchange Bitget says attackers who drained roughly $387.5 million from its hot and warm wallets got in by exploiting zero-day vulnerabilities in two third-party security appliances, then used that access to spoof transaction data and trick the exchange's own payout-authorization process into approving fraudulent withdrawals. The exchange's post-incident account, reported September 30, is the first detail on how the late-September theft happened.

The reporting is from BleepingComputer; Bitget has not published a full technical advisory, and the compromised products remain unnamed.

What happened

Per Bitget's account, attackers compromised two security appliances — referred to only as "security appliance A" and "security appliance B" — via zero-day exploits, reached a backend system inside the wallet infrastructure, and spoofed transaction data so that fraudulent payouts looked routine to the authorization logic. Timeline as Bitget describes it:

  • August 31, 2026 — earliest observed malicious activity.
  • September 24 — unauthorized access to the security appliances.
  • September 25 (02:31–05:23 UTC+8) — the funds moved.
  • September 30 — the zero-day detail disclosed.

Stolen assets spanned ETH, XRP, BNB, AVAX, USDT, USDC and others across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. Bitget says its User Protection Fund (which it puts at more than $464 million) absorbs the loss and customer balances are intact.

Figures vary by source: BleepingComputer, Fortune, and Decrypt cite $387.5 million, while Bitget's own earlier accounting and CNBC put the directly-stolen figure nearer $351.6 million. Either way it ranks as the largest crypto exchange theft of the year to date.

Attribution — hedged

CEO Gracy Chen blames North Korean state-linked hackers, citing IP-behavior patterns and on-chain analysis. That is the exchange's assessment, not an indictment or a government attribution — treat it as such. Bitget says it is working with Mandiant and SlowMist on the investigation; no vendor advisory naming the exploited appliances has been published, and no CVE has been assigned.

Action checklist

  1. Exchanges and custodians: don't trust appliance output as ground truth. The failure here was authorization logic accepting spoofed transaction data — verify payout instructions against an independent source, not just the device that could be compromised.
  2. Treat security appliances as attack surface, not just defense. Segment their management planes and monitor them for the lateral movement that follows a device compromise.
  3. Enforce out-of-band verification for large or anomalous withdrawals; a single spoofable authorization path is a single point of failure.
  4. Watch for the disclosed IOCs if and when Mandiant or SlowMist publish them — none are public yet.

Context

This fits a run of large-2026 thefts the industry has attributed to North Korea — reporting has tied the same cluster to roughly $280 million taken from Kelp and $290 million from Drift earlier in the year. The recurring pattern in these exchange hits isn't a novel cryptographic break; it's the compromise of operational infrastructure — build systems, admin consoles, and now security appliances — followed by manipulation of the money-movement logic the exchange already trusts. Until a technical post-mortem names the appliances and the flaws, the transferable lesson is narrow but real: the device you deployed to watch the network can become the way in.

Related stories