
Bitget $387.5M Theft Exploited Zero-Day in Third-Party Security Appliances A and B
Bitget confirmed a third-party zero-day enabled credential theft and lateral movement into wallet systems, draining $387.5M. Evidence from SlowMist and Mandiant shows compromise predated transfers by weeks, exposing supply-chain risks in security appliances. Independent attribution remains limited to wallet clustering while vendor details stay undisclosed.
SlowMist recovered a custom withdrawal tool and traced initial compromise to hidden scripts on Product A nodes that extracted environment variables for database access. Mandiant confirmed lateral movement from security appliance B to Bitget production wallets, deploying malicious packages after three failed command injection attempts on the management platform. The 11-blockchain drain hit hot and warm wallets across ETH, TRON, and others, with only $632k frozen so far.
Procurement records show many exchanges integrate identical third-party appliances without isolated credential stores or egress filtering on node services. This pattern matches prior incidents where vendors delayed patches after notification, allowing persistence from August into late September. Bitget disabled affected functions but the vendor remains unnamed, blocking independent verification of similar exposures elsewhere.
North Korean attribution rests on wallet overlaps reported by Elliptic and TRM Labs rather than infrastructure forensics. Independent technical evidence shows only the custom tool and C2 on appliance B; no code reuse or TTPs publicly link to known Lazarus clusters. On-chain laundering continues through mixers without new freezes reported.
Exchanges must now audit all third-party node services for environment variable exposure and mandate hardware-isolated signing. Mandiant and SlowMist probes continue; next disclosures expected within 30 days on additional affected products.
Mandiant: At least two additional exchanges using Product A or B will disclose similar compromises within 45 days.
Sources (3)
- [1]SlowMist Progress Report(https://www.slowmist.com/en/security-reports/)
- [2]Mandiant Incident Analysis(https://www.mandiant.com/resources)
- [3]The Hacker News Bitget Report(https://thehackernews.com/2026/10/bitget-confirms-third-party-zero-day.html)