Crypto exchange Bitget says the September 24 theft of about $387.5 million in digital assets started with a zero-day flaw in third-party security products, not its own code, and that attackers spent weeks building their path to the wallets before any money moved. Withdrawals have been back to normal since October 2, but the accounting is still being refined as targets dry out.
The breach ranks among the biggest exchange incidents of 2026, and the full scope only became clear gradually. Bitget’s first public estimate put losses at $351.6 million, and weeks later the figure rose to $387.5 million as the exchange accounted for more stolen Zcash and Tron tokens. On-chain analysts counting every transfer on the nine affected chains landed within a few hundred thousand dollars of the same figure.
How long the attackers had access
SlowMist’s forensic report traces the first malicious activity to August 31, more than three weeks before any funds left. That detail matters because Bitget had not yet been breached in any visible way during most of that period.
The path, according to the exchange: attackers exploited a flaw in two third-party security appliances and deployed a web shell onto one of them, then established a command channel from that foothold. From there they reached internal wallet infrastructure, moved through a network segment, and eventually triggered fraudulent withdrawal commands that looked like normal system operations to the risk checks on duty. Bitget says private keys and cold wallets were never touched, which is why customer balances survived the breach intact, a distinction that has kept depositors whole in similar incidents at other exchanges in previous cycles.
Bitget’s written account: attackers “gained unauthorized privileged access to Bitget’s third-party security appliances A and B,” deployed a web shell on appliance B, and built a command channel from there.
Where the money went
The stolen assets spread across nine blockchains within minutes of the September 24 withdrawals, with most of the movement in two quick bursts that hit five chains within seconds. The bulk of the stolen XRP was swapped into bitcoin and ether, while Zcash moved into a shielded pool where tracing becomes harder. Analysts at Elliptic and TRM Labs found wallet overlaps linking the operator to previous hacks attributed to North Korean groups.
Bitget’s response has been unusual in its speed. After freezing withdrawals on September 24, the exchange reopened bitcoin withdrawals on September 28, ether on September 29, USDT on September 30, and every remaining coin, fiat rail and P2P service by October 2. The company says the whole loss sits under its Bitget Protection Fund, which holds 5,500 BTC, about $464 million at current prices, so customer balances are covered. Framed the other way: the fund now holds less than it started with, unless it tops up.
| Date | Development |
|---|---|
| August 31 | First malicious activity traced, weeks before any loss |
| September 24 | $387.5 million in transfers across nine chains; withdrawals frozen |
| September 28 to 30 | BTC, ETH, USDT withdrawals resume in stages |
| October 2-8 | Remaining tokens, fiat rails and P2P restored |
| October 8 | Forensics name a third-party zero-day as the entry point |
The uncomfortable detail about vendors
A zero-day in third-party security products is a supply chain problem, not a coding flaw at Bitget itself, and that distinction carries little comfort when the result is still nine figures lost. Security teams buy firewalls, VPN gateways and endpoint agents on the assumption that these products harden the perimeter. As this incident shows, a single compromised appliance can become the quietest way into a network, because security tools often hold privileged network positions and are monitored less closely than application servers.
Bitget has not named the vendor publicly. BleepingComputer and The Hacker News, which followed the disclosure, note the pattern matches what has been documented in other recent intrusions, where a flaw in a network security product gave attackers a privileged position to reach deeper targets. Whether the appliance vendor has shipped a patch, and whether other customers of the same product were targeted the same way, remain open questions that Bitget’s statement does not answer.
SlowMist’s timeline also showed the attackers knew the withdrawal pipeline well enough to mimic its normal shape, which suggests some level of insider knowledge or lengthy observation. Bitget has not said whether any insider has been identified.
What it means for the market
The incident lands on a market already digesting the shutdown of the Blast layer-2 network, an ether ETF outflow streak, and the aftermath of a Twitter account takeover of Microsoft’s own profile earlier the same week. Set beside those events, the market response to a $387.5 million loss has been muted, partly because Bitget covered customer balances in full and partly because exchange hacks rarely move bitcoin the way they did in earlier years.
The bigger question is structural. If the entry point really was a third-party security product, then every exchange running the same class of appliance, and there are many, inherits a version of the same risk. Privacy and audit obligations for crypto outfits lag what banks face, and a vendor product rarely gets audited with the rigor that a custody stack gets. The remedy is boring: vendor rotation, network segmentation, and treating security tools as part of the attack surface rather than outside it. Whether exchanges will do that before the next similar incident is harder to say than whether they could.
For Bitget the immediate test is trust. Two weeks after the breach, depositors reported no failed withdrawals, and the exchange’s claim of full coverage has held up against on-chain evidence so far. The $77 million gap between the Protection Fund’s current value and the loss is the piece to watch, as it will show whether Bitget tops the fund back up or runs it lean through the next quarter.
