Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
- ID
- 30676
- Status
- summarized
- Published
- 01 Oct 2026, 1:21 PM
- Fetched
- 01 Oct 2026, 1:52 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/bitget-confirms-third-party-zero-day.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.0
- Created
- 01 Oct 2026, 1:53 PM
- Tags
- Audience
- developerssaas_founders
What happened
Bitget confirmed that the $387.5 million drained from its hot and warm wallets on September 24, 2026 was enabled by a zero-day in unnamed third-party security products, per a SlowMist investigation. Attackers used the flaw to read a database password from an environment variable, run hidden scripts on at least three nodes starting August 31, 2026, obtain high-level internal credentials, and issue withdrawal commands that bypassed existing risk controls. Funds were taken across 11 blockchains and 13 assets, and only about $632,700 was frozen by Circle, Tether, and NEAR Intents.
Why it matters
If you or a Malaysian client keep operating funds on a centralized exchange or rely on crypto rails for payouts, the concrete number here is the recovery rate: roughly $632,700 frozen against $387.5 million taken, under 0.2%. The breach did not come from Bitget's own code — it came from a third-party security product that had database credentials reachable as an environment variable — so the decision that changes is how you vet and segment vendors that sit inside your credential path, and how much you leave in hot wallets versus cold.
Discussion angle
The attacker never broke Bitget's code — they read a DB password from an environment variable on a vendor's node. Ask the room: which third-party services in your stack can read your production secrets, and would you know if a hidden script started running under one of them on August 31 and you only noticed on September 24?