Bitget — Zero-Day Exploitation in Third-Party Security Products
Publication date: September 30, 2026
Category: News / Zero-Day Exploitation
Introduction
Cryptocurrency exchange Bitget experienced a devastating cyberattack resulting in the theft of $387.5 million in digital assets from its hot and warm wallets. Independent forensic investigations conducted by blockchain security firm SlowMist and Google Cloud’s cyber-defense arm Mandiant revealed that threat actors penetrated Bitget’s core wallet environment after exploiting zero-day vulnerabilities in two third-party perimeter security appliances. The incident highlights the inherent risks within security supply chains and the sophistication of advanced threat operators.
What is Third-Party Security Appliance Exploitation? (General Analysis)
This incident involves the compromise of third-party network security appliances (identified in forensic reports as Product A and Security Appliance B). These devices, designed to protect internal networks and filter malicious traffic, served as the initial access vector due to previously unknown logical or architectural flaws (zero-days).
Since no official CVE identifier has been assigned in current public registries, we reasonably estimate classification under CWE-77 (Improper Neutralization of Special Elements used in a Command / ‘Command Injection’) or CWE-94 (Improper Control of Generation of Code), with an estimated CVSS v3.1 vector score of 9.8 (Critical: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), given that successful exploitation enabled remote code execution with elevated privileges on critical infrastructure.
How Does It Work? (Technical Analysis)
Digital forensics and incident response (DFIR) performed by SlowMist and Mandiant mapped out a precise timeline of the malicious operations:
- Initial Infection and Reconnaissance: The earliest malicious activity identified in available logs dates back to August 31. Attackers leveraged a zero-day vulnerability affecting a service running on a Product A node. This allowed them to execute a hidden script under the service process, launching commands to read environment variables containing database passwords and establish unauthorized database connections.
- Persistence and Web Shell Deployment: On September 24, 2026, threat actors gained unauthorized privileged access to security appliances A and B. On security appliance B, they deployed a web shell to secure long-term persistence and established a Command-and-Control (C2) connection.
- Lateral Movement and Exfiltration: Utilizing persistent access on security appliance B, the actors moved laterally to Bitget’s production wallet job server, deploying malicious packages and a custom withdrawal tool.
- Transaction Spoofing: Having compromised the critical backend, the attackers spoofed transaction data, tricking the exchange’s automated authorization process into transferring massive funds out of compromised hot and warm wallets between 02:31 and 05:23 UTC+8 on September 25 across multiple blockchains (Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base).
Affected Systems / Environments
- Impacted Components: Perimeter security devices and third-party appliances (generically designated as Product A and Security Appliance B).
- Internal Servers: Production wallet job server.
- Affected Cryptocurrencies: Ethereum (ETH), XRP, BNB, Avalanche (AVAX), Tether (USDT), USD Coin (USDC), and other tokens across multiple blockchains.
- Organizations: Bitget (global cryptocurrency exchange infrastructure).
Mitigation and Detection
Remediation
- Perimeter Isolation: Immediately disconnect and isolate any third-party security appliances exhibiting abnormal access logs or unauthorized spawned processes.
- Mass Credential Rotation: Invalidate and rotate all database credentials, API keys, environment variables, and authorization tokens linked to production servers and wallet infrastructure.
- Strict Network Segmentation: Enforce strict micro-segmentation and firewall rules to restrict direct communication between perimeter security appliances and internal transaction-processing servers.
Detection
- Child Process Monitoring: Audit execution logs for unexpected child processes or command interpreters (bash, sh, powershell) spawned by network device management services.
- File Integrity Monitoring: Deploy solutions to detect unauthorized modifications within web directories and appliance operating systems.
“The Bitget breach demonstrates how advanced threat actors bypass internal defenses by targeting the security supply chain, using third-party network devices as stepping stones to execute silent lateral movement into critical financial production environments.”
Wrapping Up
The security incident at Bitget, resulting in losses exceeding $387.5 million, highlights the critical vulnerability posed by third-party security appliances when exposed to zero-day attacks. The combination of perimeter compromise, web shell persistence, and transactional process manipulation underscores the urgent need for deep visibility across hybrid and network infrastructures beyond traditional endpoints.
References
- BleepingComputer. (2026). Bitget hacked via zero-day in third-party security products. Retrieved from https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/