Didn’t expect it at all—Bitget @Bitget_zh was hacked for $387.5 million this time, and the entry point was actually a third-party security device it paid for?
Conclusions from SlowMist and Mandiant: the hackers first took over two third-party security devices used by Bitget. One of them relied on a zero-day vulnerability; then they used the device to move laterally into the production environment and into the wallet server, forging transaction data. The approval process looked normal, and the money was automatically released.
The earliest malicious traces appeared on August 31, but the actual move to transfer funds didn’t happen until the early hours of September 25—after more than three weeks of lurking.
These hackers are seriously incredible—how did they pull it off? Was it done by the General Jin from Cao County again?
But the good news is that the stolen funds in this Bitget incident are covered by the protection fund, so it’s not a big issue.
Conclusions from SlowMist and Mandiant: the hackers first took over two third-party security devices used by Bitget. One of them relied on a zero-day vulnerability; then they used the device to move laterally into the production environment and into the wallet server, forging transaction data. The approval process looked normal, and the money was automatically released.
The earliest malicious traces appeared on August 31, but the actual move to transfer funds didn’t happen until the early hours of September 25—after more than three weeks of lurking.
These hackers are seriously incredible—how did they pull it off? Was it done by the General Jin from Cao County again?
But the good news is that the stolen funds in this Bitget incident are covered by the protection fund, so it’s not a big issue.

