OCTOBER 1, 2026
Subscribe
Global Press Media · World Report
Technology

Bitget Blames Zero‑Day Bug in Third‑Party Tool for $387.5 Million Crypto Theft

Bitget Blames Zero‑Day Bug in Third‑Party Tool for $387.5 Million Crypto Theft

On Wednesday, Bitget—a fast‑expanding crypto exchange—stated that the $387.5 million robbery that rattled the sector last week was made possible by an undisclosed flaw, known as a zero‑day, in a security solution provided by a third‑party vendor.

Through the exploit, hackers circumvented safeguards and transferred sizable amounts of cryptocurrency from users’ wallets on Bitget’s platform. The exchange, which provides spot trading, futures and other derivatives, said it spotted the unauthorized movements soon after they happened, leading to a swift freeze of the compromised accounts and the launch of a comprehensive forensic probe.

The incident was examined by independent security company SlowMist, which concluded that the malicious actions stemmed from the exploited zero‑day. Their report indicates the defect lay within a third‑party security product that Bitget used for network monitoring and threat detection. Since the vendor was unaware of the flaw, no fix or mitigation existed when the breach occurred.

Analysts point out that supply‑chain vulnerabilities are an escalating worry for crypto services. Although exchanges usually implement multiple layers of security, they still rely on outside tools for tasks like intrusion detection, anti‑DDoS measures and transaction monitoring. Earlier breaches—such as the 2022 Binance attack that exploited stolen API keys and the 2021 Poly Network compromise—demonstrate how perpetrators can exploit the most fragile component of a multifaceted security framework.

Bitget responded by stating it is working with law‑enforcement bodies in several jurisdictions and has initiated an extensive audit of its security architecture. The platform committed to collaborating with the third‑party supplier to create a patch and is assessing ways to reimburse impacted users according to its internal risk‑management guidelines.

The incident revives demands from regulators and industry associations for tighter supervision of third‑party software employed by crypto platforms. Experts forecast that exchanges will boost spending on internal security functions and apply stricter vetting of outside vendors. As the probe proceeds, Bitget’s response may become a benchmark for how the industry tackles supply‑chain weaknesses in the rapidly changing digital‑asset arena.

Source: feedburner
Editorial Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related