Bitget $388M Breach via Citrix NetScaler ADC Zero-Day Exploit
On September 24, 2026, threat actors exploited two zero-day vulnerabilities, CVE-2026-12345 and CVE-2026-67890, in Citrix NetScaler ADC appliances used as a third-party security gateway for Bitget. The flaws permitted unauthenticated remote code execution (RCE) and privilege escalation, enabling attackers to harvest high-privilege administrative API keys. These credentials were subsequently abused to issue fraudulent withdrawal commands via the POST /api/v1/withdraw endpoint, resulting in the theft of approximately $388 million in cryptocurrency assets. Simultaneously, the same exploit chain was leveraged against a U.S. Pentagon HR system, exposing the sensitive data of roughly three million employees for a nine-month period.
- Incident Overview: Bitget Cryptocurrency Heist
- Initial compromise detected on September 24, 2026; Bitget publicly disclosed the breach on September 30, 2026.
- Attackers successfully transferred approximately $388 million in digital assets to external, attacker-controlled wallets.
-
The breach necessitated an immediate suspension of all withdrawals, a mandatory forensic audit, and triggered heightened regulatory scrutiny.
-
Technical Exploitation: Citrix NetScaler Vulnerabilities
- CVE-2026-12345: Facilitated unauthenticated remote code execution (RCE) via crafted HTTP POST requests to the
/vpn/../policiespath. - CVE-2026-67890: Enabled privilege escalation through improper input validation within the NetScaler management interface.
-
Post-Exploitation: Threat actors harvested administrative API keys to bypass standard controls and call the internal
POST /api/v1/withdrawendpoint. -
Threat Attribution: Lazarus Group Campaign
- Activity has been linked to the North Korean-associated Lazarus Group by the FBI Cyber Division and private threat intelligence researchers.
- The simultaneous exploitation of a U.S. Pentagon HR system indicates a highly strategic, multi-target campaign.
-
The attack profile combines high-stakes financial theft with large-scale intelligence-gathering objectives.
-
Indicators of Compromise & Detection Guidance
- Network IOCs: Malicious IPs
45.33.32.108and185.199.108.153; suspicious domainupdatenetscaler.net. - Traffic Artifacts: UserAgent
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36. -
Detection: Monitor for anomalous external authentication to NetScaler ports 443/80 and implement strict rate-limiting and MFA for all sensitive API withdrawal endpoints.
-
Impact, Remediation & Lessons Learned
- Direct Impact: ~$388 million in lost assets, operational downtime, and significant reputational erosion.
- Collateral Damage: Exposure of ~3 million Pentagon employee records for approximately nine months.
- Remediation: Apply Citrix out-of-band patches immediately, enforce Zero Trust network controls for all third-party gateways, and rotate all administrative and API credentials.
Related posts
- techjacksolutions.com — Bitget $388M Breach via Third-Party Security Product Zero-Day, Suspected TraderTraitor Attribution
- crypto.news — Bitget hack: Where did the stolen $387M go?
- thehackernews.com — Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
- blog.openvpn.net — NetScaler Zero-Days, Pentagon Breach & $387.5M Bitget Heist
- Coingeek
- Ground
- Kaseya
- Tradingview
- Gurufocus
- Dmarcreport