Bitget says wallet theft came through zero-day flaws in security appliances
The breach cut across Bitget’s wallet operations, forcing it to stop withdrawals while it tries to contain and recover the stolen funds.
Bitget says last week’s $387.5 million theft came from attackers who used zero-day flaws in third-party security appliances to reach its wallet environment, making this a supply-chain-style compromise rather than a direct wallet-only breach. SlowMist and Mandiant both said the intruders first took over security devices, then pivoted to Bitget’s production wallet job server and used tooling that enabled the withdrawals. Bitget halted withdrawals after spotting unauthorized transfers from hot and warm wallets, and CEO Gracy Chen said the incident touched assets including ETH, XRP, BNB, AVAX, USDT and USDC across several chains. The company also launched a Recovery Bounty Program that pays 5% to people who help freeze or recover the stolen funds.
Why it matters
For Bitget users, the key change is that the theft was not limited to the wallet itself: attackers reached the wallet environment through third-party security products and then moved into production systems. That widens the trust boundary around exchange infrastructure and helps explain why withdrawals were suspended while Bitget works to freeze or recover assets across multiple blockchains.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer