bleeping-computer · Crawled Oct 1, 2026

Bitget hacked via zero-day in third-party security products

1 IoCs
Read original article ↗

AI Summary

Cryptocurrency exchange Bitget was breached in a $387.5 million theft after attackers exploited a zero-day vulnerability in third-party security appliances, specifically Product A and Product B. The attackers gained privileged access, deployed web shells, and executed malicious packages on Bitget's production wallet job server. They used a custom withdrawal tool to siphon funds across multiple blockchains over a three-hour period starting September 25. Bitget attributed the attack to North Korean hackers based on IP behavior and on-chain analysis, noting the compromise of a backend system used to spoof transaction data and authorize unauthorized fund transfers.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Filename custom withdrawal tool Details →