Published: · Region: Global · Category: cyber

Bitget Confirms $387.5 Million Theft via Zero-Day in Third-Party Security Product

Crypto exchange Bitget says attackers used a previously unknown flaw in a third-party security product to steal $387.5 million, moving from compromised appliances into its wallet environment and deploying malicious packages. The case underlines how a weakness in trusted security infrastructure can put customer funds and platform stability at risk.

Investigators say a major cryptocurrency theft at Bitget started not with a simple phishing email but with a hidden flaw in the company’s own defensive tools.

Bitget has confirmed that attackers exploited a zero‑day vulnerability in a third‑party security product to steal $387.5 million. Incident responders at Mandiant reported that the intruders first compromised the security appliances, then used that access to move into Bitget’s wallet environment.

Once inside, the attackers deployed malicious packages on the server responsible for wallet jobs. From there, they were able to siphon digital assets on a large scale.

The pattern echoes tactics seen in other campaigns. Separate research has detailed how Citrix NetScaler attackers used a second‑stage payload to create a superuser account and conceal a PHP web shell behind URLs that looked like cascading style sheets. The same Perl script staged configuration data for upload, changed /bin/sh permissions and erased itself after running.

For Bitget customers, the core fact is that hundreds of millions of dollars in assets were removed. The exchange has not yet publicly specified how the loss will be handled, whether users will be fully compensated, or what impact the theft will have on withdrawals and trading.

For other crypto platforms and financial firms, the incident highlights the risk that comes from deep‑inside‑the‑network security tools. Third‑party appliances often sit at central points in infrastructure and hold elevated privileges. A zero‑day in such a product gives attackers a path around perimeter defenses and into sensitive systems such as wallets and transaction processors.

The Bitget breach comes as security researchers are also drawing attention to other ways attackers bypass traditional perimeter controls, including malicious OAuth applications that can gain full mailbox access after a single user click, and stealthy post‑exploitation techniques on core network services.

Regulators and policymakers are likely to scrutinize how a vulnerability in a security product led to such a large loss at a platform that serves users across borders. Questions will focus on vendor security practices, Bitget’s own oversight of its suppliers, and whether current rules on disclosure and consumer protection are adequate for exchanges with this level of exposure.

Key developments to watch include public identification of the affected security product and any patches or advisories its vendor issues, signs that other organizations using the same product may have been targeted, and how Bitget manages customer communications and liquidity in the aftermath. Any law enforcement attribution could also connect the theft to known criminal or state‑linked groups and shape international responses.

Sources