Bitget Confirms $387.5 Million Theft Linked to North Korean Hackers
Article Content
- •Bitget confirmed a theft of $387.5 million linked to a zero-day vulnerability.
- •The attack involved unauthorized transfers from hot and warm wallets across 11 blockchains.
- •Bitget has resumed some transactions and plans full service restoration by October 2, 2026.
Cryptocurrency exchange Bitget confirmed that a theft of approximately $387.5 million was executed using a zero-day vulnerability in third-party security products. The attack, which began on September 24, 2026, involved unauthorized transfers from Bitget's hot and warm wallets. Bitget's investigation, conducted by SlowMist, revealed that attackers exploited a flaw to gain internal credentials and issue fraudulent withdrawal commands. The incident affected 11 blockchains, including Ethereum and XRP, and led to the freezing of $632,700 in assets by various platforms. The company has since resumed some customer transactions and plans to restore all services by October 2, 2026. Initial estimates of the stolen amount were lower but were revised after further analysis. The methods used in the attack are reportedly consistent with tactics employed by North Korean hacker groups.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Bitget in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What was the total amount stolen?
What vulnerabilities were exploited?
When will all services be restored?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…