
Cryptocurrency exchange Bitget says the attackers who stole $387.5 million from its hot and warm wallets last week broke in by exploiting zero-day vulnerabilities in two third-party security appliances, not by phishing an employee or cracking a wallet key. Two separate investigations, by blockchain security firm SlowMist and Google’s Mandiant, put the earliest malicious activity on August 31, when a service on one appliance node was exploited and a hidden script read a database password from the process environment.
On September 24 the intruders gained privileged access to both appliances, planted a web shell on one, and used that foothold to move sideways to Bitget’s production wallet job server, where they installed malicious packages and a custom withdrawal tool. Roughly three hours of transfers across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base followed in the early hours of September 25. Bitget’s CEO has attributed the theft to North Korean hackers based on IP behavior and on-chain analysis, and says the attackers spoofed transaction data so the exchange’s own authorization process approved the withdrawals. Bitget has not named the vendors or products involved, and it has opened a 5% recovery bounty for anyone who helps freeze or recover the stolen funds.
The lesson for defenders is that the security stack itself was the entry point: edge and monitoring appliances sit close to sensitive systems, run with broad privileges, and are often patched and monitored less closely than the servers they protect.
