← Back to blog

Bitget Blames Third-Party Zero-Day in $387.5M Crypto Heist

Attackers exploited a zero-day flaw in third-party security tools to steal $387.5 million from cryptocurrency exchange Bitget. The breach highlights risks of supply chain vulnerabilities in critical infrastructure.

TL;DR

  • Bitget lost $387.5 million in a recent cyberattack.
  • SlowMist investigation traced the breach to a zero-day in third-party security software.
  • Attackers used a custom tool to exploit the vulnerability.
  • The exchange is working with security firms to recover assets.
  • Organizations should audit third-party security dependencies.

Cryptocurrency exchange Bitget has confirmed that a devastating $387.5 million theft was made possible through a previously unknown zero-day vulnerability in third-party security products. According to findings from blockchain security firm SlowMist, attackers leveraged a custom-built tool to exploit weaknesses in external software integrated into Bitget's infrastructure.

The breach underscores the growing threat posed by supply chain attacks, where vulnerabilities in trusted third-party components can lead to catastrophic losses. As organizations continue to rely heavily on external vendors for security solutions, this incident serves as a stark reminder of the need for rigorous vetting and continuous monitoring of all integrated technologies.

Attack Vector and Investigation Insights

  • The attack exploited a zero-day vulnerability in third-party security software used by Bitget.
  • Blockchain security firm SlowMist led the investigation and identified a custom malware tool used in the breach.
  • No evidence suggests that Bitget’s core systems were directly compromised.
  • Funds were drained across multiple transactions shortly after the initial compromise.

Implications for Enterprise Security Teams

  • Organizations must extend their security reviews to include third-party vendor assessments.
  • Supply chain attacks are increasingly common and difficult to detect without proactive monitoring.
  • Relying solely on external vendors for security can introduce blind spots and unpatched risks.
  • Incident response plans should account for breaches originating from partner ecosystems.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.