$ techbeacon▋
CVE & Exploits

Bitget Attributes $387.5 Million Heist to Third‑Party Zero‑Day Flaw

Bitget Attributes $387.5 Million Heist to Third‑Party Zero‑Day Flaw

Cryptocurrency exchange Bitget announced on Wednesday that the $387.5 million theft reported last week was enabled by a zero‑day vulnerability in a third‑party security product used by the platform.

The exchange cited findings from security firm SlowMist, which said its investigation uncovered malicious activity that directly leveraged the undisclosed flaw. SlowMist’s report links the exploit to the initial breach that allowed attackers to move large volumes of digital assets out of Bitget’s wallets.

Zero‑day vulnerabilities are software bugs that are unknown to the vendor and therefore lack an available patch. In the case of Bitget, the weakness lay not in its own code but in a security tool supplied by an external vendor, underscoring the risks exchanges face when they rely on third‑party solutions for protection against hacking.

The loss adds to a string of high‑profile cryptocurrency thefts that have shaken confidence in the sector this year. While the exact number of affected customers has not been disclosed, the magnitude of the theft—equivalent to hundreds of millions of dollars in fiat terms—highlights how quickly large sums can be siphoned when a single vulnerability is exploited.

Bitget said it is working closely with law‑enforcement agencies and forensic teams to trace the stolen funds and pursue legal recourse. The exchange also promised a comprehensive security review, including an audit of all third‑party services, to prevent similar incidents in the future.

Industry observers note that the episode may accelerate calls for stricter oversight of security practices at crypto platforms. Regulators in several jurisdictions have already expressed concern about the adequacy of risk‑management frameworks employed by exchanges, and this breach could prompt new guidelines on third‑party risk assessment.

SlowMist’s analysis remains ongoing, and Bitget has not provided a timeline for when additional details will be released. The incident serves as a reminder that even well‑funded exchanges remain vulnerable when a hidden flaw in a supporting product is weaponized, and it may spur a broader push for transparency and rapid patching of security software across the cryptocurrency ecosystem.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related