Bitget Zero-Day Hack Hit 11 Chains; Funds Flee to Zcash

Bitget confirmed attackers used a third-party zero-day to steal $387.5 million, while wallets moved $3.9 million into Zcash's shielded Ironwood pool.

Read as article

Bitget Zero-Day Hack Hit 11 Chains; Funds Flee to Zcash

By @sharedot · · 7 pages

  • Crypto
  • Bitget
  • Zero Day
  • Zcash
  • North Korea

Bitget confirmed attackers used a third-party zero-day to steal $387.5 million, while wallets moved $3.9 million into Zcash's shielded Ironwood pool.

What Happened: A Zero-Day, Not an Insider Leak

Bitget on Wednesday confirmed that attackers who stole $387.5 million from its hot and warm wallets on September 24 exploited a zero-day flaw in third-party security products, relying on SlowMist's ongoing investigation. The exchange said the flaw let the attacker obtain high-level internal credentials and issue fraudulent withdrawal commands that bypassed existing risk controls. Bitget has notified the relevant vendor and disabled the affected functionality pending a fix, according to The Hacker News.

A Month-Long Intrusion, Then a Custom Theft Tool

SlowMist's progress report places the earliest malicious activity on August 31, 2026, when a hidden script on one Product A node read an environment variable containing a database password, with similar activity on other nodes on September 23 and 25. On September 25, the actor used an internal employee's identity to reach a second product's management platform, attempting command injections. A bespoke withdrawal tool, tailored to the wallet system's logic, began executing at 01:49 a.m. that day, per SlowMist and TechNadu.

Mandiant: Web Shell and Lateral Movement

Google-owned Mandiant's probe found the threat actor compromised two third-party security appliances, deployed a web shell on appliance B, and established a command-and-control connection. Using that persistent access, the actor moved laterally into Bitget's production wallet job server and deployed malicious packages, then controlled the wallet job server to distribute them. On-chain activity spanning roughly 2 hours and 52 minutes drained assets across 11 blockchains, including Ethereum, TRON, Zcash, Base, and Arbitrum, TechNadu reports.

North Korea Attribution and Zcash Laundering

Bitget says IP behavior patterns and on-chain analysis point to North Korean threat actors, with Elliptic and TRM Labs uncovering wallet overlaps used to launder proceeds from previous hacks. Meanwhile, CoinDesk's review, first flagged by ZachXBT, found about $3.9 million — 2,746 ZEC — moved into Zcash's Ironwood shielded pool across three transfers on Wednesday, roughly 15% of the ZEC stolen. Ironwood hides senders, recipients and amounts, making the funds harder to trace.

Stakes and What Comes Next

Only about $1.1 million has been frozen so far — by Circle, Tether, and NEAR Intents — a tiny fraction of the $387.5 million taken, TechNadu notes. Investigators can still compare timing and amounts if funds later re-emerge from the shielded pool, but Ironwood's privacy makes recovery increasingly difficult. Bitget has temporarily halted withdrawals, resumed Bitcoin withdrawals earlier, disabled the affected third-party functionality, and is awaiting the vendor's fix, The Hacker News and Grafa report.

Sources

  1. thehackernews.com › Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
  2. technadu.com › Bitget Confirms Zero-Day Flaw Behind More Than $387 Million Crypto Theft
  3. grafa.com › Bitget hackers move $3.9 million into Zcash

More on Crypto

Bitget Zero-Day Hack Hit 11 Chains; Funds Flee to Zcash · ShareDot