Bitget said the $387.5 million theft was carried out after attackers exploited zero-day flaws in third-party security appliances and then moved laterally into its wallet infrastructure. Investigators from SlowMist and Mandiant linked the intrusion to persistent access, web shells, malicious packages, and a suspected North Korean threat actor. #Bitget #SlowMist #Mandiant #NorthKoreanHackers
Keypoints
- Attackers breached Bitget through zero-day flaws in third-party security products.
- SlowMist and Mandiant found web shells and malicious packages on compromised systems.
- The intrusion spread to Bitgetβs production wallet job server and wallet environment.
- Multiple hot and warm wallet transfers drained $387.5 million across several blockchains.
- Bitget blamed North Korean hackers and launched a Recovery Bounty Program.