Cryptocurrency exchange Bitget said attackers behind last week’s theft of $387.5 million gained access to its systems by exploiting zero-day flaws in third-party security products.
Preliminary investigations conducted by blockchain security firm SlowMist and Google Cloud’s Mandiant found that the attackers compromised two security appliances used by Bitget. The attackers then installed a web shell on one device and moved into a production wallet server, where they deployed malware and a custom withdrawal tool.
SlowMist said the earliest malicious activity was detected on August 31. The attackers later used the compromised systems to access sensitive data and move through Bitget’s infrastructure.
The cryptocurrency theft took place on September 25 and continued for nearly three hours across several blockchains, according to SlowMist. The stolen assets included ETH, XRP, BNB, AVAX, USDT and USDC.
Bitget suspended withdrawals after detecting unauthorized transfers from its hot and warm wallets. CEO Gracy Chen said the attack affected multiple blockchain networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base.
Chen also attributed the attack to North Korean hackers, citing IP activity and blockchain analysis. At present, this claim has not been confirmed.