Bitget confirms zero-day vulnerability used in $387.5M hot-wallet exploit

CIE News ·

Bitget confirmed a third-party zero-day flaw led to a $387.5 million breach across 11 chains, while investigators noted custom tools bypassed risk controls and partners froze $50.3 million.

Crypto exchange Bitget confirmed that an attacker drained $387.5 million from its hot wallets in a multi-chain breach lasting nearly three hours on September 25. According to forensic findings reported by ministryofcyberaffairs.com, security firm SlowMist determined the breach originated from a zero-day vulnerability in a third-party security product dating back to August 31, followed by administrative abuse on September 25.

SlowMist reported that the intruder deployed a customized tool designed specifically to forge Bitget risk-control parameters and execute automated withdrawals across 11 blockchains. The drain began with initial transfers in Tron (TRX) and Ethereum (ETH) before moving across multiple networks, with an estimated $185 million taken within the opening minute. Investigators noted that cold wallets and private keys remained uncompromised despite the automated system manipulation.

The exploit has been linked to the Lazarus Group, with Bitget CEO Gracy Chen requesting external protocols to freeze illicit addresses. According to Bitcoin.com News, cross-chain protocol Thorchain declined requests to blacklist associated wallets, stating the network cannot selectively block specific addresses. Stablecoin issuers Tether and Circle, alongside NEAR Intents, have frozen $50.3 million in stolen funds, while Bitget plans to tap its User Protection Fund to cover impacted client balances.