LW40: Bitget's breach path, Ethereum loaders, and shortcut campaigns
Executive Summary
Last week’s reporting filled in the technical path behind the $387.5 million Bitget theft. Investigators found that the attacker reached the exchange’s production wallet environment through compromised third-party security systems, then used a custom withdrawal tool to forge risk-control parameters. On-chain analysts tracked the proceeds across multiple networks, bridges, swaps, and laundering services.
Developer compromise remained active. PolinRider loaders in 35 GitHub repositories recovered rotating command servers from Ethereum transactions before installing Node.js and Python stealers. In South Korea, AhnLab documented six spear-phishing patterns built around malicious shortcuts and HWP files, while Security Alliance published new infrastructure associated with UNC1069 and an uncategorized fake Zoom cluster.
Key Trends
1. The Bitget intrusion bypassed wallet controls without stealing private keys
SlowMist traced malicious activity in the available logs to August 31, when the attacker exploited a zero-day affecting a third-party security product. Later activity involved a second security product and access to its management platform through an internal employee identity. Investigators recovered a custom withdrawal tool that forged risk-control parameters, built withdrawal requests, and invoked Bitget’s wallet process. The tool ran 42 minutes before the first verified on-chain transfer.1
Rekt’s reconstruction, drawing on the SlowMist and Mandiant findings, placed the attacker on Bitget’s production wallet job server after privileged access to third-party security appliances. Bitget found no evidence that private keys were stolen, and its cold wallets were unaffected. The exchange’s normal signing workflow executed the forged requests, allowing about $387.5 million to leave across several networks.2
The case separates custody of signing keys from control of the systems that tell those keys what to sign. Monitoring must cover administrative access to security appliances, lateral movement into wallet orchestration hosts, and discrepancies between risk-engine decisions and transactions submitted by backend services.
2. Laundering crossed chains faster than manual tracing could follow
Chainalysis said the attackers moved $387 million in 23 initial transfers across Ethereum, XRP Ledger, Zcash, and Tron. The proceeds then passed through cross-chain liquidity and messaging protocols, instant swaps, mixers, decentralized exchanges, and laundering services. Investigators matched deposits and payouts across protocols, including XRP converted into Bitcoin, and traced funds to monitored attacker-controlled addresses. Chainalysis attributed the theft to DPRK actors and said it pushed North Korea-attributed cryptocurrency theft in 2026 above $1 billion.3
The company used investigator-directed AI automation to reconcile bridge activity and said one task that would have required more than 20 hours of manual work took under 10 minutes. Investigators defined the tracing logic and reviewed the results rather than delegating attribution or investigative judgment to the system.3
ZachXBT reported that Chinese illicit actors were laundering Bitget proceeds for the alleged DPRK attackers and seeking operational help in public Discord and Telegram channels. He observed funds moving through bridges and into services including Wasabi, and linked one alias to laundering from the earlier Kelp DAO exploit. He said the pattern matched activity seen after several TraderTraitor-attributed thefts.4
3. PolinRider hid rotating command servers in Ethereum transactions
SafeDep confirmed PolinRider loaders at the default-branch tip of 35 GitHub repositories. The loader searched Ethereum blocks for transactions from operator wallets, decoded two IP address and port pairs from each recipient address, and fetched later stages from those servers. Two wallets exposed 11 command servers, and related infrastructure appeared in 70 malicious npm and PyPI records tracked by OpenSSF.5
The malicious code sat in build scripts, test fixtures, package patches, and code-generation tasks that developers or CI systems would run frequently. One rejected pull request placed the loader in 20 files and forged a maintainer’s author metadata. On WSL2 hosts, the loader also launched node.exe, crossing from the Linux guest into Windows.5
Later stages stole process environment variables, browser passwords and cookies, Git credentials, and cryptocurrency wallet-extension data. The Python component also targeted source code and other developer files. Public blockchain transactions made command-server rotation resilient, but they also left a permanent record that defenders could use to recover historical infrastructure.
4. Shortcut campaigns reused Windows tools and public services
AhnLab documented six spear-phishing patterns targeting organizations in South Korea during August. LNK files accounted for the largest share of detections. The chains used embedded PowerShell, AutoIt, curl.exe, scheduled tasks, GitHub or Google Drive delivery, PubNub command traffic, and DLL side-loading. Later stages included information stealers, keyloggers, Python backdoors, and XenoRAT-type malware.67
Several chains paired a visible decoy with persistence and remote access. One registered a task disguised as a OneDrive update and exchanged commands through PubNub. Another downloaded an HTA, then loaded credential theft and backdoor components in memory. A third used a resume-themed shortcut and injected a backdoor into a legitimate process through DLL side-loading.67
Security Alliance handled two DPRK-related cases involving a fake Microsoft Teams link and a Telegram account takeover report, with no losses reported. It also published 11 domains associated with UNC1069. A separate set of four fake Zoom domains belonged to an uncategorized intrusion cluster that Security Alliance tracks as SINT-69.8
What to Watch
Cryptocurrency services should monitor the systems that construct and approve withdrawals, not only private-key access. Alert on administrative sessions to security appliances, new web shells or outbound command traffic from those systems, lateral movement into wallet job servers, and withdrawal requests whose backend risk parameters do not match recorded policy decisions. Preserve host and identity telemetry long enough to reconstruct access that began weeks before the theft.
Development teams should review frequently executed build and test files for long whitespace runs, obfuscated code, unexpected eval calls, and commits whose author and committer metadata do not agree. Network monitoring can connect unusual Ethereum RPC calls from Node.js with later requests to raw IP addresses. Windows investigations should correlate shortcut or HWP execution with hidden PowerShell, renamed native tools, scheduled tasks, public code-hosting downloads, and PubNub traffic.
Reports Reviewed
How AI Helped Chainalysis Investigators Trace the $387 Million North Korea Stole from Bitget ↩︎ ↩︎
Chinese illicit actors laundering Bitget exploit funds for alleged DPRK attackers ↩︎
PolinRider Switches to Ethereum C2 in 30+ Repositories ↩︎ ↩︎
August 2026 Threat Trend Report on APT Attacks (South Korea) ↩︎ ↩︎