bleeping-computer · Crawled Oct 1, 2026
Bitget hacked via zero-day in third-party security products
1 IoCs
Read original article ↗
AI Summary
Cryptocurrency exchange Bitget was breached in a $387.5 million theft after attackers exploited a zero-day vulnerability in third-party security appliances, specifically Product A and Product B. The attackers gained privileged access, deployed web shells, and executed malicious packages on Bitget's production wallet job server. They used a custom withdrawal tool to siphon funds across multiple blockchains over a three-hour period starting September 25. Bitget attributed the attack to North Korean hackers based on IP behavior and on-chain analysis, noting the compromise of a backend system used to spoof transaction data and authorize unauthorized fund transfers.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | custom withdrawal tool | Details → |