Wire Observer.
Technology

Bitget Attributes $387.5 Million Crypto Heist to Zero‑Day Flaw in Third‑Party Security Tool

Bitget Attributes $387.5 Million Crypto Heist to Zero‑Day Flaw in Third‑Party Security Tool

Bitget, a rapidly growing cryptocurrency exchange, announced on Wednesday that the $387.5 million theft that shocked the industry last week was facilitated by a previously unknown vulnerability—commonly called a zero‑day—in a security product supplied by an external vendor.

The breach allowed attackers to bypass protective measures and move large sums of digital assets out of user wallets on Bitget’s platform. The exchange, which offers spot trading, futures and other derivative products, confirmed that the illicit transfers were detected shortly after they occurred, prompting an immediate freeze of affected accounts and a full‑scale forensic investigation.

Independent cybersecurity firm SlowMist, which was engaged to analyze the incident, reported that malicious activity traced back to the exploited zero‑day. According to the firm’s findings, the flaw resided in a third‑party security solution that Bitget relied upon for network monitoring and threat detection. Because the vulnerability was unknown to the vendor, no patch or mitigation was available at the time of the attack.

Security experts note that supply‑chain risks have become a growing concern for crypto‑related services. While exchanges typically build layered defenses, they also depend on external tools for functions such as intrusion detection, anti‑DDoS protection and transaction monitoring. Past incidents—including the 2022 Binance hack that leveraged compromised API keys and the 2021 Poly Network exploit—have highlighted how attackers can target the weakest link in a complex security ecosystem.

In response, Bitget said it is cooperating with law enforcement agencies across multiple jurisdictions and has begun a comprehensive review of its security architecture. The exchange pledged to work with the third‑party vendor to develop a patch, and it is exploring options to compensate affected users in line with its internal risk‑management policies.

The episode reignites calls from regulators and industry groups for stricter oversight of third‑party software used by crypto platforms. Analysts predict that exchanges will increase investment in in‑house security capabilities and conduct more rigorous vetting of external providers. As investigations continue, Bitget’s handling of the fallout could set a precedent for how the sector addresses supply‑chain vulnerabilities in the fast‑evolving digital‑asset space.

Source: feedburner
Kabir Rao — Security desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related