Friday, 2 October 2026 0 calls on file SearchSubscribe
Crypto and finance news. On the record.
Breaking
Crypto4 min read

Investigators Tie the Bitget Theft to a Third-Party Flaw

Mandiant and SlowMist found that compromised third-party security products enabled unauthorized access to Bitget's wallet environment in the 24 September theft. News pages, not the short update, put the loss at $387.5 million.

Investigators Tie the Bitget Theft to a Third-Party Flaw
Illustration: Called It

An exchange, two security firms, and two newsrooms are not all saying the same sentences about a September theft, and the difference is the point. The Bitget SlowMist Mandiant zero-day September 30 2026 record starts with Bitget's support update that day. Mandiant, part of Google Cloud, and SlowMist had reports out. Both found that compromised third-party security products enabled unauthorized access to Bitget's wallet environment.

What happened

The incident the investigators describe is the 24 September theft. Bitget's 30 September update says those two reports are out and states what both found. A third-party security product is software the exchange did not write itself and uses to protect its systems. Compromised means that product was used as a way in.

Unauthorized access to the exchange wallet environment means someone reached the systems where the exchange's wallets sit, without permission. That path is the finding Bitget's update and both investigators share. Bitget's update is here.

A zero-day, in plain words, is a flaw the vendor has not yet fixed in public, so an attacker can use a hole the defense has not patched. BleepingComputer, on 30 September, and The Hacker News, on 1 October, say Bitget put the theft at $387.5 million and described a zero-day in third-party security products. The dollar figure and the zero-day description are in those news pages.

The short Bitget update page does not itself state the dollar figure. The product finding, compromised third-party security products enabling the access, is what belongs to the update together with Mandiant and SlowMist. The news pages are where the $387.5 million figure is attributed to Bitget.

The same two news pages say Bitget attributed the attack to North Korean actors based on IP behavior and on-chain analysis. An attribution is a claim about who did it. IP behavior is how the network addresses in the intrusion acted. On-chain analysis is the public ledger trail of the assets after they moved.

The short update does not itself state the North Korea claim. The attribution, like the dollar figure, stays with BleepingComputer and The Hacker News as their report of what Bitget said. BleepingComputer's account is here. The Hacker News's account is here.

Why it matters

The sourcing split should not be sanded flat. There is a finding Bitget, Mandiant, and SlowMist can all be cited for: compromised third-party security products enabled unauthorized access to the wallet environment. There is a pair of claims the news pages report and the short update does not state. Those are the $387.5 million theft figure and the attribution to North Korean actors.

The zero-day description is also in the news pages' account of what Bitget said. Putting the dollar figure or the country into the short post would make that post say something it does not say. The pages can still be quoted. They have to be quoted as themselves.

Third-party products are a structural point. An exchange can lock down its own code and still inherit a flaw in a tool it runs at the door. The investigators' shared finding is that this is the path that opened. The brand of the product is not in the facts used here, and it is not guessed.

The dates have to stay apart. The theft the investigators describe is 24 September. The update that says the Mandiant and SlowMist reports are out is 30 September.

Moving either date onto the other day would misstate the record. The incident is the earlier date. The reports being public, in Bitget's telling, is the later one.

Attribution to North Korean actors is a serious claim, which is why it stays inside the outlets that report it. BleepingComputer and The Hacker News say Bitget made the attribution on the basis of IP behavior and on-chain analysis. These sources do not include a government notice adopting the same conclusion. An exchange attribution reported by two newsrooms is not that notice.

The sum is likewise a news-page attribution to Bitget, not a line lifted from the short update. It is specific enough to repeat exactly. $387.5 million is the figure. Rounding it into a different headline number would be a change the pages are not cited here as making.

Related: NEAR Intents exploit and MetaMask Lido incident.

What's next

What the Mandiant and SlowMist reports contain beyond the shared finding is not reproduced here. The shared finding is unauthorized access through compromised third-party security products. Finer detail on the flaw, any patch, or a vendor response is outside the facts used here.

The news pages add the zero-day description, the dollar figure, and the North Korea attribution, all as Bitget's account. A later exchange post could put the sum and the attribution on the short page itself. Until it does, the short update and the news pages remain different texts.

No recovery total and no named vendor appear in the materials used here. The state of the record is simpler than a single blended paragraph. Investigators had published, in Bitget's telling on 30 September, about a 24 September theft.

They agreed on the class of door. Two newsrooms said Bitget had numbered the loss and named the actors.

This article is for information only and is not investment advice.

More from Crypto

All crypto

The Morning Call.

The day's crypto and finance news, one call and one chart. Weekdays at 7am ET.