Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

A staggering $388 million in cryptocurrency has been stolen from Bitget, a Singapore-based digital asset exchange, after an attacker exploited a flaw in a third-party security product. The heist highlights the importance of robust cybersecurity measures and the need for vigilance against vulnerabilities in even the most trusted software.

The incident is believed to have occurred through a sophisticated attack that leveraged a weakness in a cross-domain privilege escalation (CDPE) vulnerability. In simple terms, CDPE allows attackers to bypass security restrictions by exploiting differences in access controls between separate systems or networks. This can provide a backdoor into otherwise secure environments and enable unauthorized access to sensitive data.

Bitget has been tight-lipped about the specifics of the attack, but experts suspect that an attacker exploited a flaw in a third-party security product, likely a web application firewall (WAF), which is designed to protect against common web attacks. WAFs are crucial components of modern cybersecurity defenses, as they can help prevent SQL injection and cross-site scripting (XSS) attacks by filtering out malicious traffic.

The attack on Bitget demonstrates the critical importance of understanding how CDPE vulnerabilities can be exploited in real-world scenarios. A CDPE vulnerability is essentially a pathway for attackers to navigate through multiple systems or domains, ultimately reaching their target. This concept might sound abstract, but its implications are straightforward: when an attacker finds a way to exploit such a vulnerability, they can potentially gain access to sensitive areas of a system.

The incident also underscores the importance of monitoring and patching vulnerabilities in third-party software products. Many organizations rely on these tools to safeguard their systems, but they often fail to keep them up-to-date with the latest security patches. This can leave gaps in defenses that savvy attackers can exploit. As we’ve seen time and again, a single weak link in the chain can be enough for an attacker to breach even the most robust security posture.

For those who manage or operate digital infrastructure, this incident serves as a stark reminder of the need for continuous monitoring, patching, and vulnerability management. Organizations should prioritize regular updates and maintenance of their third-party software products, including WAFs, to prevent attacks like this one from occurring in the future.


Source: The Hacker News — 2026-09-28