North Korean Hackers Steal $387.5m From Crypto Platform Bitget Using A Zero-Day Flaw To Drain Its Wallets

The firm’s forensic investigation has identified a custom withdrawal tool used by the attackers.

Published on Oct 1, 2026
Alex Blake Written by Alex Blake
Bitget hacked for $387

Cryptocurrency platform Bitget has suffered a huge breach that saw attackers make off with $387.5 million in pilfered funds. Now, the exchange has revealed that the threat actors’ exploit centered on a zero-day vulnerability in a third-party security tool.

According to an investigation carried out by blockchain security firm SlowMist on Bitget’s behalf, the funds were removed from Bitget’s hot wallet on September 25 (UTC+8), but the earliest malicious activity was detected nearly a month prior on August 31.

On that date, a service running on a node belonging to one of the third-party tools was hit by a zero-day vulnerability. This involved the attackers running a hidden script under the service process. They then initiated a command that read the environment variable that stored the database password, with the intruder then connecting to the database. A similar pattern of activity was seen on other third-party nodes on September 23 and September 25.

Early in the morning of September 25, the hackers made their next move. This involved harnessing the hijacked identity of an internal employee to target a third-party management platform used by Bitget. This began at 00:07 (UTC+8) when the attackers made three consecutive attempts to inject system commands into the platform that would allow them to write malicious files.

They then submitted code through the platform’s web execution endpoint, with the goal being to alter the server’s configuration, write a communication relay file, and then upload and assemble their own files in a series of batches.

The final step was exfiltrating funds from Bitget. SlowMist said it had recovered a custom withdrawal tool the attackers had deleted, and it shed light on their methodology. The tool was highly tailored to its target, forging risk-control parameters, constructing withdrawal requests and invoking Bitget’s withdrawal process. It began the process of removing funds from the platform at 01:49 on September 25.

Moving the funds

The first transfer was completed at 02:31 on September 25, when 93 TRX was sent to an attacker-controlled address. Eleven seconds later, 0.84 ETH (worth about $2,262 at the time of writing) was sent to one of the attacker’s wallets in what was likely a test transaction. The transfers then got underway in earnest and continued for around 2 hours and 52 minutes, finishing at 05:23 on September 25.

Finally, the threat actors tried to modify withdrawal records in order to trigger additional fund movements. These returned errors and occurred after 05:22 on September 25.

In all, the hackers made off with $387.5 million, one of the largest cryptocurrency thefts to date. The sophistication and success of the attack has prompted some to link it to North Korean state groups, which are known to put a particular focus on cryptocurrency platforms.

Indeed, Bitget CEO Gracy Chen has stated that investigators uncovered IP addresses linked to VPN services known to be used by North Korean threat actors, according to CNBC. As well as that, Chen argued that the attack’s pattern resembled others thought to have been conducted by North Korea.

In an email to customers, Bitget said that “the financial impact caused by the incident has been covered by the Bitget Protection Fund, while user account balances remain completely unaffected.” It added that the company’s Protection Fund – which is designed to cover eventualities such as the recent hack – had been replenished and now contained more than $300 million.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Alex Blake
Alex Blake Journalist

Alex Blake is a freelance journalist who has been covering the tech world for over a decade. In that time he's interviewed Apple VPs, reviewed countless products and taken deep dives into the pressing issues of the day. You'll find his work at TechRadar, Macworld, PC Gamer, T3 and more.