Bitget, one of the major cryptocurrency exchanges, has revealed new details about the cyberattack that led to the theft of around $387.5 million in digital assets. The attack was discovered on September 24, 2026, after unauthorized transfers were detected from some of the exchange’s hot and warm wallets. According to Bitget, the attackers gained access by exploiting a zero-day vulnerability in a third-party security product used within its systems. The vulnerability allowed the attackers to obtain high-level internal credentials and move deeper into the exchange’s infrastructure.

After gaining access, the attackers used the stolen credentials to send fraudulent withdrawal commands to Bitget’s wallet systems. These commands were made to appear like legitimate administrative activity, allowing them to bypass existing security and risk-control checks. The attackers first carried out two small test transfers before moving to much larger transactions about 30 minutes later. Bitget said these initial transfers stayed below its risk-control threshold and did not trigger alerts. The larger transfers were then processed from affected hot and warm wallets across several blockchain networks.

The stolen amount was initially estimated at $351.6 million but was later revised to approximately $387.5 million after further investigation and reconciliation of transactions. The affected assets included cryptocurrencies such as ETH, XRP, USDT, USDC, ZEC, BNB, AVAX and TRX. Bitget has stated that its cold wallets were not affected during the incident, and the company’s investigation found no compromise of private keys. Bitget also said that customer account balances were not affected by the attack and that the incident was contained after the affected systems were isolated.

Security researchers have since uncovered evidence suggesting that the attackers may have been active inside the environment weeks before the September 24 theft. SlowMist reported that malicious activity connected to the attack could be traced back to August 31 and involved a zero-day vulnerability affecting a third-party security product. Investigators also identified activity involving two third-party security products and a wallet application host. The findings indicate that the attackers spent time gaining access and preparing their attack before finally transferring the cryptocurrency from Bitget’s wallets.

Following the discovery, Bitget suspended withdrawals as a security precaution and began isolating affected infrastructure. The company said it identified and remediated the underlying vulnerability, revoked and reissued internal credentials, restricted access to sensitive systems and strengthened withdrawal verification. Bitget also added additional monitoring for unusual activity and notified the relevant third-party vendor. Mandiant and SlowMist are supporting the ongoing forensic investigation, while Bitget is working with law enforcement and industry partners to trace and recover the stolen assets.

The incident highlights how a vulnerability in a third-party security product can become an entry point into highly sensitive systems even when an organization has its own security controls in place. Bitget has said it will review how third-party security products are assessed and deployed across its infrastructure. The company’s investigation and asset-recovery efforts are still ongoing, while further technical findings are expected in its formal incident report. At this stage, Bitget says the attack has been contained, the underlying vulnerability has been remediated and no further unauthorized transfers have been identified.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news