MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-01 · via The Hacker News

Bitget Exchange Breach Traced to Third-Party Security Software Vulnerability Costing $387.5 Million

Image via The Hacker News
Image via The Hacker News

Cryptocurrency exchange Bitget confirmed that the $387.5 million theft from the previous week resulted from attackers exploiting a zero-day vulnerability in third-party security software, according to investigation findings from security firm SlowMist. The attackers used a custom-built tool to leverage the flaw and gain unauthorized access to the platform's systems. The incident underscores supply-chain security risks where vulnerabilities in auxiliary security products can compromise high-value targets.

Expanded Detail

Bitget, a major cryptocurrency trading platform, fell victim to a significant security incident last week resulting in the loss of $387.5 million in digital assets. Following an investigation conducted by SlowMist, a recognized cybersecurity firm, the breach's root cause was identified as a zero-day vulnerability—a previously unknown security flaw—embedded in third-party security software integrated with Bitget's infrastructure. The attackers demonstrated sophistication by developing custom tools specifically designed to exploit this vulnerability and penetrate the exchange's defenses.

This incident highlights a critical vulnerability in modern security infrastructure: organizations protecting high-value digital assets can be compromised not through direct attacks on their primary systems, but through weaknesses in supplementary security tools they depend upon. Supply-chain security, particularly regarding third-party software used to enhance platform safety, emerges as a significant operational risk for cryptocurrency exchanges and similar institutions handling substantial financial resources.

Context

The breach may significantly impact cryptocurrency investors and the broader digital asset market, as it could erode confidence in exchange security practices and raise scrutiny regarding vendor risk management across the industry. Cryptocurrency users may reconsider where they store digital holdings, potentially affecting trading volume and platform adoption. The incident could accelerate industry-wide demands for more rigorous third-party software auditing and stricter security certifications, ultimately reshaping how cryptocurrency platforms evaluate and implement auxiliary security solutions.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
Fifth Cisco SD-WAN Vulnerability Actively Exploited by Attackers This Year · Cybersecurity
Fortinet Email Gateway Vulnerability Under Active Attack, Added to Federal Tracking List · Cybersecurity
Kiteworks Fixes Critical Code Injection Flaw in Email Security Gateway · Cybersecurity
OpenSSL Releases Patch for DTLS Memory Exposure and Denial-of-Service Vulnerability · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft.” Browse more stories.