Bitget drained of $387.5 million after zero-day exploit in security appliances

CIE News ·

Mandiant and SlowMist revealed attackers exploited a third-party zero-day to steal $387.5 million from Bitget, prompting exchange reserves to cover the loss.

Attackers stole $387.5 million from Bitget on September 24, 2026, following a breach that began nearly four weeks prior, according to forensic investigations released by Mandiant and SlowMist. Reports published by bleepingcomputer.com show the intruders leveraged a zero-day flaw in third-party security appliances starting on August 31, 2026. The threat actors established lateral access to Bitget's production wallet job server to deploy malware and forge legitimate withdrawal requests without compromising private keys.

The unauthorized transfers spanned 2 hours and 52 minutes, siphoning assets across Ethereum, Arbitrum, Avalanche, Optimism, BNB Chain, Base, and the XRP Ledger. Bitcoin.com News reported that Arkham Intelligence tracked $228 million leaving within the first 18 minutes alone, with Ripple (XRP) accounting for approximately $153 million. The stolen assets also included Ether (ETH), TRON (TRX), Zcash (ZEC), and multiple stablecoins, which attackers have been laundering across decentralized protocols including CoW Protocol and Chainflip.

Following the incident, Bitget recorded $463 million in net outflows over 24 hours. Bitget CEO Gracy Chen confirmed that the exchange's User Protection Fund is covering all user losses and will be replenished to exceed $300 million within a week. Withdrawals are resuming in phases, starting with Bitcoin (BTC), and the exchange has introduced a 5% recovery bounty program to help freeze and retrieve the stolen funds.