Threat Intelligence

Bitget Confirms Zero-Day in Third-Party Security Tools Behind $387.5 Million Crypto Theft

The Hacker News · 1 Oct 2026
Key Takeaway Businesses relying on third-party security or financial platforms should ensure vendors have rapid patching processes and should monitor for unusual internal credential use, even in supposedly trusted tools.

Bitget has confirmed that the $387.5 million cryptocurrency theft disclosed on September 24, 2026 was carried out using a zero-day vulnerability in third-party security products. According to investigation findings from SlowMist, attackers used the flaw to obtain high-level internal credentials, which were then used to issue fraudulent withdrawal commands that bypassed Bitget's existing risk controls. A customised attack tool used to initiate the unauthorised withdrawals has since been recovered.

The breach affected 11 blockchains, including Ethereum, TRON, XRP Ledger, and BNB Smart Chain, with assets such as XRP, ETH, USDT, and USDC among those stolen. Around $632,700 has since been frozen by Circle, Tether, and NEAR Intents. SlowMist's timeline traces the earliest malicious activity back to August 31, 2026, when a hidden script was run on a compromised node to read database credentials, with similar activity observed again in September before the funds were ultimately moved.

The attackers are also reported to have accessed a separate security product's management platform using a compromised internal employee identity, attempting to inject malicious commands into the system. Bitget has notified the affected vendor and disabled the vulnerable functionality while a fix is developed, though the investigation is still ongoing.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.