Cookie Consent by Free Privacy Policy Generator

Bitget confirms zero-day vulnerability behind $387.5 million cryptocurrency theft

Cryptocurrency exchange Bitget has confirmed that attackers who stole $387.5 million last week exploited a zero-day vulnerability in third-party security products. The confirmation follows an ongoing investigation conducted with blockchain security firm SlowMist, which identified malicious activity involving the third-party tools and recovered a customised tool used by the attacker. Bitget has not disclosed which third-party security product was affected, but the incident highlights the operational risk that organisations face when relying on external security tooling, particularly in high-value environments such as cryptocurrency exchanges where attackers are highly motivated and well-resourced.

Why this matters for UK organisations

This incident is a reminder that supply chain risk extends beyond software development dependencies to include the security products organisations use to protect themselves. Many organisations deploy third-party security tools for endpoint protection, network monitoring, identity management or cloud security without fully understanding how those tools are maintained, how vulnerabilities are disclosed, or what happens if the tool itself becomes the attack vector. In this case, the attackers appear to have identified and exploited a previously unknown flaw in a product that Bitget relied on for security, turning a defensive control into an entry point. Whilst the financial services and cryptocurrency sectors face particularly sophisticated threats, the lesson applies broadly: security tooling is software, and software has vulnerabilities. For UK businesses, this raises important questions about how third-party security products are assessed, maintained and monitored, and whether over-reliance on any single product creates a concentration of risk that could be exploited.

What to review

UK businesses should review whether third-party security products are included in vulnerability management processes, whether vendors provide timely security updates, and whether there is a clear process for responding if a security tool is found to be compromised. It is worth checking whether security products are deployed with the same rigour as other critical systems: are they monitored for unusual behaviour, are they included in incident response plans, and is there a fallback if they fail or are compromised? Organisations should also consider whether they have visibility into the security posture of the vendors providing these tools, including how they handle vulnerability disclosure, how quickly they patch, and whether they have experienced previous security incidents. This is also a prompt to review whether over-reliance on any single security product creates a concentration of risk. Many organisations deploy security tools in layers precisely to avoid this problem, but it is worth confirming that those layers are genuinely independent and that a compromise in one tool would not cascade to others.

Source: The Hacker News

News and blog posts
Today's brief reflects a pattern UK organisations will recognise: the need to...
The National Cyber Security Centre has issued urgent guidance calling on UK...
Google Threat Intelligence Group has published research examining vulnerability...
Cryptocurrency exchange Bitget has confirmed that attackers who stole $387.5...