Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Bitget, a Singapore-based cryptocurrency exchange, has confirmed that a third-party zero-day vulnerability was exploited in a massive heist that saw hackers siphon off nearly $387.5 million worth of digital assets from users’ accounts. The brazen attack highlights the ongoing risks faced by the cryptocurrency industry and underscores the importance of robust security measures to prevent such incidents.

The hack, which occurred on September 29th, was initially attributed to a complex series of events involving phishing attacks, social engineering, and exploits targeting vulnerabilities in Bitget’s systems. However, further investigation revealed that the root cause of the breach lay with a third-party vendor that provided software services to the exchange. This zero-day vulnerability, which had not been previously discovered or patched, allowed attackers to bypass security protocols and access sensitive user data.

To understand how this attack unfolded, it’s essential to grasp the concept of cross-domain privilege escalation. Essentially, when multiple domains (or systems) are connected, an attacker can exploit vulnerabilities in one domain to gain elevated privileges within another. In this case, the third-party vendor’s software created a backdoor that enabled hackers to escalate their privileges and access sensitive data on Bitget’s platform.

The scope of the attack is staggering – with nearly $387.5 million stolen from users’ accounts. This not only has significant financial implications for affected individuals but also erodes trust in cryptocurrency exchanges, which are already vulnerable to regulatory scrutiny and public perception challenges. The fact that a zero-day vulnerability was exploited highlights the need for more robust security measures, including regular software updates, penetration testing, and incident response planning.

The incident serves as a stark reminder of the importance of supply chain security in preventing cyber attacks. Bitget’s reliance on third-party vendors has led to a breach that could have been mitigated with more stringent controls and oversight. As the cryptocurrency industry continues to grow, it’s crucial for exchanges and other stakeholders to prioritize security measures that extend beyond their own systems to include those of their suppliers.

In light of this attack, we urge users to exercise caution when dealing with cryptocurrency exchanges and third-party vendors. While Bitget has taken steps to address the breach and restore user trust, it’s essential for individuals to remain vigilant and monitor their accounts closely for any suspicious activity. By staying informed about security best practices and being mindful of potential risks, we can all contribute to a safer digital landscape for cryptocurrency users.


Source: The Hacker News — 2026-10-01