Bitget Says Attackers Used Zero‑Day in Third‑Party Security Product to Steal $387.5 Million
Crypto platform Bitget confirms attackers abused a previously unknown flaw in a third‑party security product, moved into its wallet environment, and stole about $387.5 million, according to incident responder Mandiant.
One of the largest reported crypto thefts this year began with a hidden weakness in a specialised security tool.
Bitget has confirmed that attackers exploited a zero‑day vulnerability in a third‑party security product to steal roughly $387.5 million. Incident‑response firm Mandiant, which investigated the breach, found that intruders first compromised security appliances before moving deeper into Bitget’s infrastructure.
From that initial foothold, the attackers were able to reach Bitget’s wallet environment. Mandiant reports that they then deployed malicious packages on a wallet job server, a system used to handle operations tied to digital asset wallets.
By compromising systems that manage or automate wallet‑related tasks, attackers can gain routes to interfere with transfers or access funds at scale. The fact that the initial entry point was a security product underscores how much access and trust such tools hold inside complex networks.
The next steps to watch are how Bitget handles compensation and remediation for users, what details emerge about the affected third‑party product and its patch status, and whether regulators treat this case as grounds to tighten expectations on how exchanges vet and monitor critical security vendors.
Sources
- OSINT