Bitget Hack — SlowMist and Mandiant Zero-Day Attribution (September 30, 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3KkwXr…TLLYSummary
On September 24, 2026, cryptocurrency exchange Bitget suffered a theft of approximately $387.5 million from hot and warm wallets after attackers exploited a zero-day vulnerability in an unnamed third-party security product. On September 30, 2026, SlowMist and Mandiant published interim joint forensic findings tracing the earliest malicious activity to August 31, 2026 — nearly four weeks before any funds moved. Multiple investigators have alleged links to North Korean threat actors, specifically the TraderTraitor cluster within Lazarus Group, though no formal government attribution had been issued as of the report date.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(10 events)
31 August 2026
Earliest malicious activity identified: attacker exploited a zero-day vulnerability in third-party security Product A, executed a hidden script to read a database password from an environment variable, and accessed the database.
Crypto Times / SlowMist interim forensic report23 September 2026
Hidden-script activity observed on additional Product A nodes, extending attacker foothold.
Crypto Times / SlowMist interim forensic report24 September 2026
Threat actor gained unauthorized privileged access to security appliances A and B using stolen internal employee credentials. A web shell was deployed on Product B and C2 connection established. Lateral movement to Bitget's production wallet job server followed, with malicious packages deployed.
CoinTelegraph / BleepingComputer — SlowMist and Mandiant findings24 September 2026
At 18:31 UTC, two small test transfers were executed staying below risk-control thresholds. Approximately 30 minutes later, large-scale theft began. Funds transferred from hot and warm wallets across multiple blockchains for approximately 2 hours 52 minutes, ending at 21:23 UTC. Total stolen: approximately $387.5 million.
The Hacker News / Gizmodo25 September 2026
Bitget publicly disclosed the breach. CEO Gracy Chen stated North Korea was 'very likely' responsible and confirmed the User Protection Fund would cover losses. Withdrawals were suspended.
Gizmodo / HackRead25 September 2026
Bitget hidden-script activity observed on a third Product A node (per SlowMist logs).
Crypto Times / SlowMist interim forensic report26 September 2026
Bitget announced phased withdrawal resumption scheduled for September 28. User Protection Fund confirmed above $464 million.
Bitget Security Breach Loss — Cryptonomist28 September 2026
ZachXBT published allegations naming five operators — identified by aliases Cc, jack, Melon, lolo/Marin, and HELP ME — as alleged Chinese money launderers moving funds on behalf of the suspected DPRK attackers. One alias (lolo/Marin) was also alleged to be linked to the Kelp DAO exploit from April 2026.
ZachXBT via Crypto Times28 September 2026
Bitget CEO Chen stated in an interview that the attacker had tested Bitget's risk controls with small transfers before the main theft.
The Block30 September 2026
SlowMist and Mandiant published interim joint forensic findings attributing the earliest access to August 31, 2026. SlowMist separately reported that suspected hackers were routing stolen assets through CoW Protocol and Chainflip into Bitcoin, using automated scripts that set CoW order recipients to Chainflip deposit contract addresses.
Crypto Times / CoinTelegraph / TechFlowPostDecision Log
- hash: 4dpD1Z6PJqX9XaVpPg2Y5ENZWi764Rkr7aNq4ftaxyPw
This investigation is cryptographically anchored to the Solana blockchain (1 event). 19 of 20 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/30/2026, 12:14:05 PM
last updated: 9/30/2026, 6:34:38 PM
avoid.net — verified advice for a post-truth world