Skip to main content
AVOID.NET

Bitget Hack — SlowMist and Mandiant Zero-Day Attribution (September 30, 2026)

avoid.net/bitget-hack-slowmist-and-mandiant-zero-day-attribution-september-30-2026→18/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3KkwXr…TLLY

Summary

On September 24, 2026, cryptocurrency exchange Bitget suffered a theft of approximately $387.5 million from hot and warm wallets after attackers exploited a zero-day vulnerability in an unnamed third-party security product. On September 30, 2026, SlowMist and Mandiant published interim joint forensic findings tracing the earliest malicious activity to August 31, 2026 — nearly four weeks before any funds moved. Multiple investigators have alleged links to North Korean threat actors, specifically the TraderTraitor cluster within Lazarus Group, though no formal government attribution had been issued as of the report date.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Bitget Hack — SlowMist and Mandiant Zero-Day Attribution (September 30, 2026)?

Timeline(10 events)

31 August 2026

Earliest malicious activity identified: attacker exploited a zero-day vulnerability in third-party security Product A, executed a hidden script to read a database password from an environment variable, and accessed the database.

Crypto Times / SlowMist interim forensic report

23 September 2026

Hidden-script activity observed on additional Product A nodes, extending attacker foothold.

Crypto Times / SlowMist interim forensic report

24 September 2026

Threat actor gained unauthorized privileged access to security appliances A and B using stolen internal employee credentials. A web shell was deployed on Product B and C2 connection established. Lateral movement to Bitget's production wallet job server followed, with malicious packages deployed.

CoinTelegraph / BleepingComputer — SlowMist and Mandiant findings

24 September 2026

At 18:31 UTC, two small test transfers were executed staying below risk-control thresholds. Approximately 30 minutes later, large-scale theft began. Funds transferred from hot and warm wallets across multiple blockchains for approximately 2 hours 52 minutes, ending at 21:23 UTC. Total stolen: approximately $387.5 million.

The Hacker News / Gizmodo

25 September 2026

Bitget publicly disclosed the breach. CEO Gracy Chen stated North Korea was 'very likely' responsible and confirmed the User Protection Fund would cover losses. Withdrawals were suspended.

Gizmodo / HackRead

25 September 2026

Bitget hidden-script activity observed on a third Product A node (per SlowMist logs).

Crypto Times / SlowMist interim forensic report

26 September 2026

Bitget announced phased withdrawal resumption scheduled for September 28. User Protection Fund confirmed above $464 million.

Bitget Security Breach Loss — Cryptonomist

28 September 2026

ZachXBT published allegations naming five operators — identified by aliases Cc, jack, Melon, lolo/Marin, and HELP ME — as alleged Chinese money launderers moving funds on behalf of the suspected DPRK attackers. One alias (lolo/Marin) was also alleged to be linked to the Kelp DAO exploit from April 2026.

ZachXBT via Crypto Times

28 September 2026

Bitget CEO Chen stated in an interview that the attacker had tested Bitget's risk controls with small transfers before the main theft.

The Block

30 September 2026

SlowMist and Mandiant published interim joint forensic findings attributing the earliest access to August 31, 2026. SlowMist separately reported that suspected hackers were routing stolen assets through CoW Protocol and Chainflip into Bitcoin, using automated scripts that set CoW order recipients to Chainflip deposit contract addresses.

Crypto Times / CoinTelegraph / TechFlowPost
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 19 of 20 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/30/2026, 12:14:05 PM

last updated: 9/30/2026, 6:34:38 PM

avoid.net — verified advice for a post-truth world