Bitget confirmed that the $387.5 million theft from its hot and warm wallets was enabled by a zero-day flaw in third-party security products, with investigations from SlowMist and Mandiant showing the attackers used compromised appliances to move laterally and trigger unauthorized withdrawals. Bitget and blockchain security firms also linked the operation to North Korean threat actors, while frozen assets and evidence of a custom theft tool point to a highly targeted campaign across multiple blockchains. #Bitget #SlowMist #Mandiant #NorthKoreanThreatActors #Circle #Tether #NEARIntents
Keypoints
- Attackers stole $387.5 million from Bitgetβs hot and warm wallets.
- A zero-day vulnerability in third-party security products was used in the intrusion.
- SlowMist found malicious activity beginning as early as August 31, 2026.
- The attack affected 11 blockchains, including Ethereum, XRP Ledger, TRON, and BNB Smart Chain.
- Mandiant and Bitget linked the operation to North Korean threat actors.
Read More: https://thehackernews.com/2026/10/bitget-confirms-third-party-zero-day.html