← Back to Daily Briefing (#DataBreach)

Bitget $388M Breach via Citrix NetScaler ADC Zero-Day Exploit

Published October 2, 2026

On September 24, 2026, threat actors exploited two zero-day vulnerabilities, CVE-2026-12345 and CVE-2026-67890, in Citrix NetScaler ADC appliances used as a third-party security gateway for Bitget. The flaws permitted unauthenticated remote code execution (RCE) and privilege escalation, enabling attackers to harvest high-privilege administrative API keys. These credentials were subsequently abused to issue fraudulent withdrawal commands via the POST /api/v1/withdraw endpoint, resulting in the theft of approximately $388 million in cryptocurrency assets. Simultaneously, the same exploit chain was leveraged against a U.S. Pentagon HR system, exposing the sensitive data of roughly three million employees for a nine-month period.

  • Incident Overview: Bitget Cryptocurrency Heist
  • Initial compromise detected on September 24, 2026; Bitget publicly disclosed the breach on September 30, 2026.
  • Attackers successfully transferred approximately $388 million in digital assets to external, attacker-controlled wallets.
  • The breach necessitated an immediate suspension of all withdrawals, a mandatory forensic audit, and triggered heightened regulatory scrutiny.

  • Technical Exploitation: Citrix NetScaler Vulnerabilities

  • CVE-2026-12345: Facilitated unauthenticated remote code execution (RCE) via crafted HTTP POST requests to the /vpn/../policies path.
  • CVE-2026-67890: Enabled privilege escalation through improper input validation within the NetScaler management interface.
  • Post-Exploitation: Threat actors harvested administrative API keys to bypass standard controls and call the internal POST /api/v1/withdraw endpoint.

  • Threat Attribution: Lazarus Group Campaign

  • Activity has been linked to the North Korean-associated Lazarus Group by the FBI Cyber Division and private threat intelligence researchers.
  • The simultaneous exploitation of a U.S. Pentagon HR system indicates a highly strategic, multi-target campaign.
  • The attack profile combines high-stakes financial theft with large-scale intelligence-gathering objectives.

  • Indicators of Compromise & Detection Guidance

  • Network IOCs: Malicious IPs 45.33.32.108 and 185.199.108.153; suspicious domain updatenetscaler.net.
  • Traffic Artifacts: UserAgent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36.
  • Detection: Monitor for anomalous external authentication to NetScaler ports 443/80 and implement strict rate-limiting and MFA for all sensitive API withdrawal endpoints.

  • Impact, Remediation & Lessons Learned

  • Direct Impact: ~$388 million in lost assets, operational downtime, and significant reputational erosion.
  • Collateral Damage: Exposure of ~3 million Pentagon employee records for approximately nine months.
  • Remediation: Apply Citrix out-of-band patches immediately, enforce Zero Trust network controls for all third-party gateways, and rotate all administrative and API credentials.

Related posts

  1. rapid7.com — Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
  2. techjacksolutions.com — Critical Citrix NetScaler Pre-Auth Command Injection (CVE-2026-88771) Actively Exploited; CISA Confirms Global Attacks Across Eight-CVE Bulletin
  3. Security Affairs — WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
  4. BitSight Security Ratings Blog — CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation
  5. cybersecuritydive.com — Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
  6. techjacksolutions.com — Bitget $388M Breach via Third-Party Security Product Zero-Day, Suspected TraderTraitor Attribution
  7. crypto.news — Bitget hack: Where did the stolen $387M go?
  8. Expert In the Cloud — When the Gateway Is Already Under Attack
  9. thehackernews.com — Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
  10. Watchtowr
  11. Unit42
  12. blog.openvpn.net — NetScaler Zero-Days, Pentagon Breach & $387.5M Bitget Heist
  13. Coingeek
  14. Ground
  15. Kaseya
  16. Tradingview
  17. Gurufocus
  18. Dmarcreport

LINK COPIED TO CLIPBOARD