By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Bitget Reports $388M Stolen Via Third-Party Security Flaw

Cryptocurrency exchange Bitget announced on Monday that the substantial theft of approximately $388 million was facilitated by a vulnerability within a third-party security product utilized by the exchange, rather than a direct compromise of Bitget's internal systems. The attacker exploited this flaw to acquire elevated internal credentials, which were subsequently used on September 24 to issue fraudulent withdrawal requests to Bitget's wallet infrastructure. This incident highlights the critical importance of supply chain security in the financial technology sector, where reliance on external vendors for specialized services can introduce significant risks. Bitget stated that the compromised third-party product was responsible for managing security protocols and access controls, effectively acting as a gateway that the attacker leveraged. Following the discovery of the breach, Bitget initiated an internal investigation and has been working with relevant authorities and cybersecurity experts to understand the full scope of the incident and to recover the stolen assets. The exchange has also stated that it is reviewing its vendor management processes and enhancing its security measures to prevent similar incidents in the future. The precise nature of the third-party security product and the specific vulnerability exploited have not been disclosed by Bitget, citing ongoing investigations and security concerns. However, the exchange emphasized that its core trading systems and user data remained secure throughout the event. The incident underscores a broader trend in cybersecurity where attackers increasingly target vulnerabilities in the software supply chain, which can have cascading effects on multiple downstream users. The stolen funds, amounting to $388 million, represent a significant loss for the exchange and its users, prompting concerns about the robustness of security protocols within the cryptocurrency industry. Bitget has committed to providing further updates as the investigation progresses and has outlined steps to bolster its defenses, including enhanced monitoring and auditing of third-party integrations. The exchange's statement on Monday aimed to reassure its user base by clarifying the attack vector and emphasizing that its primary operational infrastructure was not directly breached. The incident serves as a stark reminder for all financial institutions, particularly those in the rapidly evolving cryptocurrency space, to rigorously vet and continuously monitor the security posture of their third-party service providers. The financial impact of $388 million is substantial, and the reputational damage can be equally significant for a cryptocurrency exchange. Bitget's communication strategy has focused on transparency regarding the source of the breach, attributing it to an external vendor's security lapse, which differentiates it from direct system hacks. The exchange's response includes a commitment to reimbursement or compensation for affected users, though specific details on this aspect are pending the full resolution of the investigation and asset recovery efforts. The reliance on third-party security solutions is common across industries, but this event brings into sharp focus the need for stringent due diligence and ongoing security audits of these critical dependencies.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.