Executive Summary
Bitget cryptocurrency exchange suffered a devastating $387.5 million theft in September 2026 when North Korean threat actors exploited zero-day vulnerabilities in two third-party security appliances. The attackers gained initial access on August 31, deployed web shells and malware on production wallet infrastructure, then executed the theft across multiple blockchains over a three-hour period on September 25. Investigations by SlowMist and Google Mandiant revealed the attackers compromised critical backend systems used to authorize cryptocurrency transactions, ultimately spoofing the exchange's withdrawal processes to move funds from hot and warm wallets.
This incident highlights the escalating sophistication of supply chain attacks targeting cryptocurrency infrastructure, particularly as North Korean state-sponsored groups continue targeting crypto exchanges with advanced zero-day exploits and multi-stage attack methodologies.
Why This Matters Now
Supply chain compromises targeting financial infrastructure are accelerating, with state-sponsored groups increasingly exploiting zero-day vulnerabilities in third-party security products to bypass enterprise defenses and steal hundreds of millions in digital assets.
Attack Path Analysis
North Korean threat actors exploited zero-day vulnerabilities in third-party security appliances to gain initial access to Bitget's infrastructure on August 31, 2026. They escalated privileges by extracting database credentials from environment variables, moved laterally to production wallet servers, established C2 through web shells, and exfiltrated $387.5 million in cryptocurrency across multiple blockchains over a 3-hour window on September 25, causing significant business disruption and forcing withdrawal suspensions.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited zero-day vulnerabilities in two third-party security appliances (Product A and B) starting August 31, 2026, running hidden scripts under service processes to establish initial foothold
MITRE ATT&CK® Techniques
Compromise Software Supply Chain
Exploit Public-Facing Application
Web Shell
Ingress Tool Transfer
Remote Services
Credentials In Files
Runtime Data Manipulation
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
PCI DSS 4.0 – External and Internal Penetration Testing
Control ID: 11.3.2
DORA – Third-party Risk Management
Control ID: Article 8
CISA ZTMM 2.0 – Device Security and Trust
Control ID: Function 2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Information Security Policy for Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Direct exposure via cryptocurrency exchange breach, zero-day exploits targeting financial infrastructure, and compliance violations across NIST frameworks requiring enhanced supply chain security.
Computer/Network Security
Third-party security products compromised via zero-day vulnerabilities, demonstrating supply chain risks and need for enhanced threat detection across security vendor ecosystems.
Information Technology/IT
Zero-day exploitation of security appliances and lateral movement through production systems highlights critical vulnerabilities in IT infrastructure and multicloud security architectures.
Banking/Mortgage
North Korean threat actors targeting financial institutions with sophisticated supply chain attacks, requiring enhanced egress security and encrypted traffic monitoring capabilities.
Sources
- Bitget hacked via zero-day in third-party security productshttps://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/Verified
- SlowMist Investigation Progress Report - Bitgethttps://github.com/slowmist/Knowledge-Base/blob/master/open-report-V2/incident-response/SlowMist%20Investigation%20Progress%20Report%20-%20Bitget_en-us.pdfVerified
- Mandiant Status Update - Bitget Incidenthttps://img.bgstatic.com/multiLang/events/MFR26-1029_Status_Update_Bitget_0930.pdfVerified
- Bitget Recovery Bounty Programhttps://www.bitget.com/support/articles/12560603896108Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this cryptocurrency exchange attack by limiting lateral movement between security appliances and production wallet servers. The segmented architecture could have reduced the blast radius and restricted unauthorized access to critical financial infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial compromise of security appliances would likely have been contained within isolated network segments, preventing immediate access to broader infrastructure components and reducing the attack surface available for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Database credential harvesting from environment variables would likely have been constrained to specific workload boundaries, preventing broad access across multiple database nodes and limiting the scope of privilege escalation within segmented environments.
Control: East-West Traffic Security
Mitigation: Lateral movement from security appliances to production wallet servers would likely have been blocked or severely constrained, reducing attacker reachability to critical financial infrastructure and limiting deployment of malicious packages across network segments.
Control: Multicloud Visibility & Control
Mitigation: Web shell deployment and persistent C2 communications would likely have been detected and constrained through comprehensive traffic monitoring, limiting the duration and scope of command and control activities across the compromised infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized cryptocurrency withdrawals and blockchain transactions would likely have been constrained through controlled egress policies, reducing the volume and speed of financial exfiltration and limiting access to external cryptocurrency networks during the attack window.
While some cryptocurrency assets may still have been at risk, the overall financial impact would likely have been significantly reduced through constrained lateral access to wallet infrastructure and limited egress pathways for bulk exfiltration operations.
Impact at a Glance
Affected Business Functions
- Cryptocurrency Trading Platform
- Digital Asset Custody Services
- Customer Wallet Management
- Cross-Chain Transaction Processing
Estimated downtime: 7 days
Estimated loss: $387,500,000
Compromise of production wallet infrastructure affecting hot and warm cryptocurrency wallets across multiple blockchain networks including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains. Potential exposure of wallet authorization processes and transaction data systems.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement from compromised security appliances to critical wallet infrastructure
- • Deploy East-West Traffic Security controls to detect and block unauthorized service-to-service communications between security appliances and production systems
- • Enable Multicloud Visibility & Control with centralized monitoring to detect anomalous interactions and suspicious automation across wallet environments
- • Strengthen Egress Security & Policy Enforcement with FQDN filtering and application-to-internet controls to prevent unauthorized cryptocurrency transfers
- • Activate Threat Detection & Anomaly Response capabilities with behavioral baselining to identify hidden script execution and environment variable access patterns



