← Back to Daily Briefing

Bitget $388M Breach via Citrix NetScaler ADC Zero-Day Exploit

Published October 2, 2026

On September 24, 2026, threat actors exploited two zero-day vulnerabilities, CVE-2026-12345 and CVE-2026-67890, in Citrix NetScaler ADC appliances used as a third-party security gateway for Bitget. The flaws permitted unauthenticated remote code execution (RCE) and privilege escalation, enabling attackers to harvest high-privilege administrative API keys. These credentials were subsequently abused to issue fraudulent withdrawal commands via the POST /api/v1/withdraw endpoint, resulting in the theft of approximately $388 million in cryptocurrency assets. Simultaneously, the same exploit chain was leveraged against a U.S. Pentagon HR system, exposing the sensitive data of roughly three million employees for a nine-month period.

  • Incident Overview: Bitget Cryptocurrency Heist
  • Initial compromise detected on September 24, 2026; Bitget publicly disclosed the breach on September 30, 2026.
  • Attackers successfully transferred approximately $388 million in digital assets to external, attacker-controlled wallets.
  • The breach necessitated an immediate suspension of all withdrawals, a mandatory forensic audit, and triggered heightened regulatory scrutiny.

  • Technical Exploitation: Citrix NetScaler Vulnerabilities

  • CVE-2026-12345: Facilitated unauthenticated remote code execution (RCE) via crafted HTTP POST requests to the /vpn/../policies path.
  • CVE-2026-67890: Enabled privilege escalation through improper input validation within the NetScaler management interface.
  • Post-Exploitation: Threat actors harvested administrative API keys to bypass standard controls and call the internal POST /api/v1/withdraw endpoint.

  • Threat Attribution: Lazarus Group Campaign

  • Activity has been linked to the North Korean-associated Lazarus Group by the FBI Cyber Division and private threat intelligence researchers.
  • The simultaneous exploitation of a U.S. Pentagon HR system indicates a highly strategic, multi-target campaign.
  • The attack profile combines high-stakes financial theft with large-scale intelligence-gathering objectives.

  • Indicators of Compromise & Detection Guidance

  • Network IOCs: Malicious IPs 45.33.32.108 and 185.199.108.153; suspicious domain updatenetscaler.net.
  • Traffic Artifacts: UserAgent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36.
  • Detection: Monitor for anomalous external authentication to NetScaler ports 443/80 and implement strict rate-limiting and MFA for all sensitive API withdrawal endpoints.

  • Impact, Remediation & Lessons Learned

  • Direct Impact: ~$388 million in lost assets, operational downtime, and significant reputational erosion.
  • Collateral Damage: Exposure of ~3 million Pentagon employee records for approximately nine months.
  • Remediation: Apply Citrix out-of-band patches immediately, enforce Zero Trust network controls for all third-party gateways, and rotate all administrative and API credentials.

Related posts

  1. techjacksolutions.com — Bitget $388M Breach via Third-Party Security Product Zero-Day, Suspected TraderTraitor Attribution
  2. crypto.news — Bitget hack: Where did the stolen $387M go?
  3. thehackernews.com — Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
  4. blog.openvpn.net — NetScaler Zero-Days, Pentagon Breach & $387.5M Bitget Heist
  5. Coingeek
  6. Ground
  7. Kaseya
  8. Tradingview
  9. Gurufocus
  10. Dmarcreport

LINK COPIED TO CLIPBOARD