
Bitget $388M Theft Stemmed from Zero-Day in Unnamed Third-Party Wallet Security Product
Bitget lost $388 million via a zero-day in an unnamed third-party security product that supplied credentials for fraudulent withdrawals. Evidence shows test transfers and no key compromise; attribution leans on TRM wallet overlaps with TraderTraitor. The case highlights unvetted third-party dependencies in crypto custody.
The compromise began with the zero-day granting access to an internal management system. From there the attackers inserted spoofed withdrawal transactions that the wallet approval process treated as legitimate. Only hot and warm wallets were hit; cold storage remained untouched and no private keys were exposed according to Bitget's ongoing review with Mandiant and SlowMist. Evidence includes two low-value test transfers at 18:31 UTC on September 24 that evaded alerts, followed by larger movements thirty minutes later. Bitget published the receiving addresses across Ethereum, XRP, Zcash, and TRON networks and opened a recovery portal for infrastructure providers. TRM Labs noted laundering overlaps with prior TraderTraitor activity but stopped short of firm attribution. The incident exposes recurring supply-chain exposure when exchanges rely on opaque third-party security tools without independent code review. Official suspicion of North Korean actors rests on wallet heuristics rather than technical attribution data. Bitget has revoked credentials, isolated affected systems, and plans a formal report this week; regulators and auditors will likely demand disclosure of the vendor and patch status within thirty days.
Mandiant: Formal report will name the third-party vendor and confirm zero-day status within 10 days
Sources (2)
- [1]The Block(https://www.theblock.co/post/bitget-gracy-chen-hack-interview)
- [2]TRM Labs(https://www.trmlabs.com/intelligence/bitget-incident)