Stolen from hot and warm wallets: $387.5 million (Source: Bitget, as reported by BleepingComputer (September 30, 2026))
A security product can be a trusted insider. It may sit close to sensitive systems and can hold the keys to them. When it is compromised, the attacker may inherit that trust. SlowMist's finding in the Bitget case shows how: one appliance exposed a database password. This is the lesson of the breach, based on the findings the exchange has published.
On September 30, Bitget disclosed how thieves took $387.5 million from its hot and warm wallets. The entry point, it said, was zero-day exploits against two third-party security appliances. A zero-day is a flaw the vendor has not yet had a chance to fix. Two inquiries support the account. One came from the blockchain security firm SlowMist. The other came from Mandiant, the cyber-defense arm of Google Cloud. BleepingComputer reported the details.
How the attackers got in, step by step
The two firms describe different stages of the intrusion. Their dates differ, so they are worth reading side by side.
SlowMist found the earliest malicious activity in the available logs on August 31. A service on one node of the first appliance, which it calls Product A, was hit through a zero-day. The attacker ran a hidden script under that service. The script read an environment variable holding the database password, then logged in to the database. A secret stored in a configuration setting turned a software flaw into database access.
The same kind of hidden-script activity appeared on two further nodes, on September 23 and September 25.
Mandiant's forensic work covers a later stage. On September 24, it says, an intruder obtained privileged access it was not entitled to on both appliances, A and B. The intruder left a web shell on appliance B. A web shell is a small program that gives remote control through a web server. The intruder also opened a command-and-control connection, which is a channel for sending orders to a compromised machine.
Mandiant says the persistent access on appliance B was the launch point. From there, the intruder pivoted to the server that runs Bitget's wallet jobs and installed malicious packages. BleepingComputer adds that the attackers deployed malware on that job server. They also used a custom withdrawal tool to start the theft after midnight on September 25.
The way in was the security tooling
The report does not name either appliance. A Bitget spokesperson was not available to BleepingComputer to discuss the flaw or the products. That is a real limit. Readers cannot yet check whether their own estate uses the affected products.
The route is still instructive. The appliances were the entry point and the path into the wallet environment. The wallet environment itself was then compromised, including the job server that received malware.
CEO Gracy Chen said the intruders also took over a key backend system inside the wallet infrastructure. She said they then used it to feed forged transaction details into the exchange's approval step, which released the money. On that account, the check relied on inputs from a compromised system. Controls that verify a request depend on the systems that supply it.
Physical security offers a parallel. A bank can reinforce its vault door, but a thief who compromises the alarm company's equipment may gain a way inside. In Bitget's case, funds were taken from its hot and warm wallets, and the exchange suspended all withdrawals after it detected the unauthorized transfers. The source does not say who bears the loss.
What is known, and what is claimed
Chen attributes the attack to North Korean hackers. She points to patterns in IP addresses and to tracing of funds on the blockchain. That is Bitget's attribution, and the source does not show the underlying evidence. BleepingComputer notes that North Korean actors were behind the Bybit hack, in which $1.5 billion was stolen from an ETH cold wallet.
Chen said the affected assets included ETH, USDT and USDC, among others. The theft crossed seven blockchains, Ethereum and Base among them. Bitget has since launched a Recovery Bounty Program. It pays 5% to anyone who helps recover or freeze the stolen funds.
Questions to put to your security team
This is one incident, and it says nothing about every vendor. It does show where to look. Five questions follow.
First, which security appliances sit inside or beside your most sensitive systems? Ask for a list by name, not a category.
Second, what secrets do those appliances hold? Check for database passwords in environment variables and for credentials that reach production systems.
Third, what stops a compromised appliance from reaching a production server? Ask to see the network rules, not the diagram.
Fourth, would your logs show a hidden script on a security appliance? SlowMist found Bitget's earliest trace in the available logs, weeks before the theft. Ask whether your team would look there.
Fifth, does your approval process verify requests independently of the systems that send them? By Chen's account, spoofed data triggered the authorization step here.
The lesson of the Bitget case is that tools bought to reduce risk can become part of the attack surface. Treat them with the same scrutiny as anything else that holds the keys.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: BleepingComputer.





