
The company SlowMist reveals that a zero-day flaw enabled the theft of $387.5 million on the Bitget platform.
AI-generated summary
Bitget is a cryptocurrency exchange that has a protection fund to cover user losses. The attack exploited vulnerabilities in third-party security software.
A first trace, twenty-four days before the flight. Cybersecurity company SlowMist dates the oldest malicious activity found in systems linked to the Bitget hack to August 31. The fraudulent transfers, detected on September 24 in universal time, then took away nearly $387.5 million.
The investigation describes an attack carried out through two third-party security products and a server linked to the wallet management application. However, it does not yet make it possible to reconstruct all the movements of the attacker between these different components.
Key Points
SlowMist dates the intrusion to August 31, almost a month before the fraudulent transfers spotted on September 24
A flaw unknown to the publisher, with no patch available, served as a gateway for attackers
The siphoning of warm wallets places the compromise at the level of internal validation procedures
Bitget's protection fund, endowed with 300 million dollars at its creation, remains less than the stolen sum
Bitget hack: a zero-day and several compromised systems
According to the SlowMist investigation report, the first trace goes back to a service installed on a node of a security product called “Product A”. The attacker exploited a zero-day flaw, that is to say a vulnerability which did not yet have a patch available at the time of its exploitation.
A script hidden in the service's process allowed it to read an environment variable containing the database password and then connect to it. SlowMist found comparable activity on two other nodes on September 23 and 25.
During the night of September 24 to 25, the attacker also accessed the administration platform of a second security product using the identity of an employee. He then attempted to inject commands, modify the configuration of the servers and deposit several malicious files there.
The main tool recovered had been deleted by the attacker. Designed specifically for Bitget's withdrawal system, it could falsify control parameters, construct fraudulent requests, and directly call the process responsible for executing them.
The program began operating at 1:49 a.m. on September 25, according to the UTC+8 time used in the report. The first confirmed outflow on the blockchain occurred at 2:31 a.m., with 93 TRX, followed eleven seconds later by 0.84 ETH. Transfers continued for approximately two hours and fifty-two minutes across multiple networks.
Falsified withdrawals without theft of private keys
The investigation therefore locates the weakness in the infrastructure responsible for preparing and controlling withdrawals. The attacker would not have needed to directly seize the private keys: his tool transmitted fraudulent orders presented as valid to the system.
After the transfers began, he also attempted to modify the database records directly. Two fake bitcoin withdrawals were processed before failing. The logs then show views of their status and retries.
According to Bitget, the incident affected some of its hot and warm wallets, while its cold wallets remained intact. This distinction comes from the platform itself, SlowMist speaking more broadly of a theft from hot wallets. The investigation does not establish that a human signing procedure would have been directly compromised.
Bitget claims that its protection fund covered the entire loss. Created with a floor of $300 million, it held more than $464 million before the attack, more than the $387.5 million ultimately recorded. The platform also ensures that its customers' balances and its separate self-custody application are not affected.

MetaMask announced that it was managing a security incident affecting part of its infrastructure during the night of September 30 to October 1, 2026, without disclosing the breach or its extent. The publisher preemptively removed its validators operated within Lido, saying there is no immediate threat to users' wallets, while warning of potential scams exploiting the announcement.

ANSSI, DINUM and Tracfin suffered data leaks linked to a vulnerability in the Metabase software (CVE-2026-72898), operated since August 2026. ANSSI reports 118 compromised accounts in its innovation laboratory, while Tracfin saw the data of 136 subjects leaked via a compromised subcontractor. Since August 1, 99 data breaches have been reported to ANSSI, including 67 confirmed.

Apple has released iOS 26.7.1 update to fix zero-day CVE-2026-86950 in CoreGraphics. The company SlowMist warns of attacks targeting crypto wallets, although Apple has not formally linked the vulnerability to these thefts.

NEAR Intents claims to have blocked more than $50 million linked to the Bitget hack and froze an additional $503,000 using its SHIELD filter before solvers intervened.

China's Ministry of State Security claims that the anonymity of cryptocurrencies is an illusion, explaining that all transactions leave traceable traces via fiat-crypto exchanges and IP addresses, and cites the Bitfinex affair as proof, while banning the use of Bitcoin on its territory despite tolerance of detention.

Four days after Bitget's $387.5 million theft, on-chain investigator ZachXBT claims Chinese intermediaries are laundering funds on behalf of suspected North Korean attackers, publicly asking for help on Discord and Telegram when their XRP-bitcoin swaps on THORChain fail, captures of support tickets and transactions show.