By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Bitget Confirms Zero-Day Exploit in $387.5M Crypto Theft

Cryptocurrency exchange Bitget confirmed on Wednesday that attackers exploited a zero-day vulnerability in third-party security products to steal $387.5 million last week. This confirmation comes from ongoing investigation findings provided by SlowMist, a blockchain security firm. The investigation identified malicious activity that involved third-party security products, specifically highlighting a zero-day vulnerability as the entry point for the breach. Furthermore, investigators recovered a customized tool that the attacker utilized in the heist. The precise nature of the third-party security product and the specific zero-day vulnerability remain undisclosed as the investigation continues, to prevent further exploitation. Bitget has stated that it is working closely with security experts and law enforcement agencies to thoroughly investigate the incident and enhance its security measures. The exchange has also committed to compensating affected users for their losses, demonstrating a commitment to customer protection despite the significant financial impact of the attack. This incident underscores the persistent risks associated with third-party integrations in the cryptocurrency ecosystem, where a single vulnerability in an external service can have cascading and severe consequences for multiple platforms and their users. The recovery of the attacker's custom tool is a critical development, potentially offering insights into the methods and sophistication of the perpetrators. The cryptocurrency industry has been a frequent target for cybercriminals, with large-scale thefts becoming a recurring concern. The use of zero-day vulnerabilities, which are previously unknown flaws that have not yet been patched by vendors, represents a particularly challenging threat to mitigate. These exploits allow attackers to bypass standard security defenses, making them highly effective for sophisticated heists. The substantial sum of $387.5 million makes this one of the largest cryptocurrency thefts in recent memory, highlighting the significant financial stakes involved in securing digital assets. Bitget's proactive communication and commitment to user compensation are crucial steps in rebuilding trust within its user base and the broader crypto community. The ongoing collaboration with SlowMist and other security entities indicates a comprehensive approach to understanding and addressing the root cause of the breach. The recovery of the attacker's tool is a significant piece of evidence that could lead to the identification and apprehension of those responsible, as well as inform future defensive strategies against similar attacks. The incident serves as a stark reminder for all cryptocurrency platforms to rigorously vet and continuously monitor the security of their third-party dependencies, as well as to maintain robust incident response plans.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.