Bitget drained of $387.5 million after zero-day exploit breaches appliances
CIE News ·
Forensic findings revealed a zero-day exploit on third-party security appliances caused Bitget's $387.5M breach. User assets remain covered by the exchange's protection fund.
On September 24, 2026, an attacker drained approximately $387.5 million from Bitget hot and warm wallets across Ethereum (ETH), TRON (TRX), XRP Ledger (XRP), and Zcash (ZEC). Forensic investigations by SlowMist and Mandiant published on September 30, 2026, determined the breach resulted from a zero-day exploit targeting two third-party security appliances rather than stolen private keys or smart contract flaws.
Malicious activity began on August 31, 2026, when credentials were stolen through a vulnerability in an initial product before access was extended to a second system using a compromised employee identity. On September 24, 2026, the threat actor deployed a web shell, established a command-and-control connection, and moved to a production wallet job server to execute forged withdrawal commands. Stolen stablecoins were quickly swapped for ETH to avoid issuer freezes.
Bitget confirmed that private keys and cold storage were not compromised during the incident. User balances were fully covered by the exchange's $464 million User Protection Fund, and withdrawals have progressively resumed.