hacker-news · Crawled Oct 1, 2026

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Read original article ↗

AI Summary

Cryptocurrency exchange Bitget suffered a $387.5 million theft after attackers exploited a zero-day vulnerability in a third-party security product, gaining access to internal credentials and deploying malicious tools to bypass risk controls. The attackers compromised multiple nodes by running hidden scripts to extract database credentials and laterally moved into Bitget's wallet environment using compromised security appliances. Forensic analysis by SlowMist and Mandiant linked the attack to North Korean threat actors, who used a custom tool to execute unauthorized withdrawals across 11 blockchains. The breach began as early as August 31, 2026, with command-and-control established via a web shell on security appliance B.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.