Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: financial (1 article)Clear

Bitget says attacker used third party security product flaw to steal 388 million dollars

Cryptocurrency exchange Bitget said the attacker who stole about 388 million dollars gained access through a vulnerability in a third-party security product the exchange used. The attacker exploited the flaw to obtain high-level internal credentials, then on September 24 used them to reach an internal management system and insert fraudulent withdrawal commands into wallet backend services, where they were treated as legitimate. The stolen funds came from Bitget's hot and warm wallets, while its offline cold wallets were unaffected. CEO Gracy Chen described the incident publicly, confirming the earlier statement that a critical wallet backend system had been compromised and used to spoof transaction data and trigger approvals.

Check
Review third-party security products in privileged positions for patch status and blast radius, and treat their credentials as high-value targets requiring isolation.
Affected
Organizations relying on a vulnerable third-party security product can have its high-level credentials stolen and abused to command core backend systems.
Fix
Inventory and patch third-party security tooling, scope its access tightly, add out-of-band approval for high-value transfers, and monitor for anomalous internal commands.