Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
AI-summarised brief · reviewed before publication
Bitget disclosed that a hacker stole roughly $388 million by exploiting a zero‑day flaw in a third‑party security product used by the exchange. The vulnerability granted the attacker high‑level internal credentials, allowing fraudulent withdrawal commands to be injected into Bitget’s wallet backend on September 24. Two small test transfers bypassed risk controls, followed by larger moves from the exchange’s hot and warm wallets; cold wallets remained untouched. Bitget revoked and reissued credentials, disabled the compromised functionality, and is working with vendors and investigators Mandiant and SlowMist. Customer balances were not affected and the exchange’s Protection Fund will cover the loss. Withdrawals are being restored gradually, and a formal incident report is expected this week. The breach prompted review of third‑party security tools.
💡 Why It Matters
- · The incident proves that a single supply‑chain weakness can undermine sophisticated internal safeguards, compelling crypto platforms to tighten oversight of external security solutions.