Bitget

2026-09-30 • Rekt •

https://rekt.news/bitget-rekt

Thumbnail for Bitget

Attackers exploited a zero-day in an unnamed third-party security product, obtained privileged internal access, and moved laterally to Bitget's production wallet job server. A custom withdrawal tool forged risk-control parameters and caused the exchange's wallet system to transfer $387.5 million without compromising private keys or cold wallets. Much of the stolen value was converted to ETH or BTC and routed through cross-chain services, while publicly identified freezes represented only a small fraction of the loss. TRM Labs found laundering-network overlap with earlier North Korean-linked hacks and infrastructure used by TraderTraitor, but the intrusion has not been definitively attributed to the DPRK.

Indicators of Compromise

Type Value First Seen Last Seen
WALLET TBWNguTTgezw9dVorX441C6nDrZpRxY… 2026-09-25 2026-09-30
WALLET t1WgMdtND8NF7NDUuYmq8MpMj1NTCXk… 2026-09-25 2026-09-30
WALLET rwNhefsz1UQEusxhCvHip3RANinWi4C… 2026-09-25 2026-09-30
WALLET 0x770b10b273fc44fe9197d6bf20f14… 2026-09-25 2026-09-30

Related Reports

« Back