BREACH WATCH BRIEF Critical ☁️ Breach

Bitget Confirms Third‑Party Zero‑Day Exploited in $387.5M Cryptocurrency Theft

Cryptocurrency exchange Bitget confirmed that attackers stole $387.5 million by exploiting a zero‑day vulnerability in a third‑party security product. The breach highlights the systemic risk of supply‑chain flaws and the need for robust vendor oversight in trust‑and‑control programs.

SeverityCritical
Type☁️ Breach
ConfidenceHigh
ReportedOct 1, 2026
Financial Services & FinTech Cryptocurrency exchanges and digital‑asset custodians Customers holding crypto on platforms that rely on third‑party security tools Third-Party Dependency
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

Bitget reported that a zero‑day flaw in a third‑party security solution was used to bypass controls and transfer $387.5 million from its hot‑wallets. The investigation, conducted with SlowMist, recovered a custom tool used by the attackers and is ongoing.

Why it matters for trust and compliance

  • The incident underscores how a missing control over third‑party security products can lead to massive asset loss, emphasizing the importance of continuous vendor‑risk monitoring and defensible evidence of due diligence.
  • Demonstrates the need for continuous monitoring of third‑party security posture as part of audit‑ready evidence.
  • Shows how a single vendor‑oversight control satisfies multiple framework requirements, delivering a unified trust signal.

Who is affected

Cryptocurrency exchanges and digital‑asset custodians Customers holding crypto on platforms that rely on third‑party security tools

Recommended actions

  1. Create a comprehensive inventory of all third‑party security products and assess their vulnerability‑management processes.
  2. Implement continuous vendor‑risk monitoring that captures remediation evidence for audit readiness.
  3. Update incident‑response playbooks to include supply‑chain compromise scenarios and run tabletop exercises.
  4. Require vendors to provide documented proof of timely patching for identified flaws and store that evidence in a centralized Trust Center.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.