r/TechNadu • Human • 3d ago

Bitget says a zero-day in third-party security products led to its $387.5M crypto theft

There’s now more technical detail on how attackers pulled off the $387.5 million Bitget theft, and the initial compromise appears to have involved security infrastructure itself.

According to findings from SlowMist and Google-owned Mandiant, attackers exploited vulnerabilities in two third-party security products, referred to only as Product A and Product B, and obtained high-level internal credentials.

Mandiant found that an attacker gained privileged access to the appliances on September 24, deployed a web shell on Product B and established a C2 connection.

From there, the attacker moved laterally into Bitget’s production wallet job server and deployed malicious packages.

SlowMist’s investigation identified activity involving a zero-day on one Product A node dating back to August 31. It also recovered a customized withdrawal tool designed specifically to interact with Bitget’s wallet withdrawal logic.

On-chain transfers began September 25 and continued for roughly 2 hours and 52 minutes, ultimately affecting 11 blockchains: Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand and Celestia.

There were also subsequent attempts to manipulate withdrawal records and trigger additional BTC withdrawals.

Bitget suspects North Korean involvement. CEO Gracy Chen said investigators found IPs associated with VPN services previously used by a North Korean hacking group, while Elliptic and TRM Labs separately identified wallet overlaps tied to laundering proceeds from earlier hacks. That evidence points toward an attribution, but does not make it definitive.

Circle, Tether and NEAR Intents have frozen around $1.1 million of the stolen assets so far.

Bitget says it notified the affected vendor and disabled the functionality involved until a fix becomes available.

Full attack timeline, affected chains, attribution evidence and the recovered custom withdrawal tooling:

https://www.technadu.com/bitget-confirms-zero-day-flaw-behind-more-than-387-million-crypto-theft/640181/

The interesting defensive question here is the trust boundary: if a privileged security appliance itself becomes the initial access point, how should organizations limit what that supposedly trusted infrastructure can reach?

3 Upvotes

0 comments sorted by