Blog · Security

Crypto Exchange Bitget Hit by Third-Party Security Bug

· 2TInteractive · generated daily-pipeline

Crypto Exchange Bitget Hit by Third-Party Security Bug

Bitget, a cryptocurrency exchange stole $388 million after a third-party security product flaw was exploited by attackers.

Cryptocurrency exchange Bitget suffered a significant security breach on September 24, 2026, after attackers exploited a zero-day vulnerability within a third-party security product. The attack resulted in the theft of approximately $388 million, according to a report by The Hacker News. Bitget disclosed that internal high-level credentials were compromised, allowing attackers to send fraudulent withdrawal commands to the exchange's wallet system. This incident highlights a common risk in cybersecurity: the vulnerabilities in third-party solutions that can undermine the security of an entire system.

What makes this case particularly troubling is the scope of the breach. The attackers gained access by leveraging a flaw in a product designed to enhance security rather than introducing new vulnerabilities. The incident highlights the inherent risks of relying on third-party security tools without thorough vetting and ongoing monitoring. Furthermore, the significant dollar amount lost underscores the potential impact such breaches can have on cryptocurrency exchanges and their users. As the incident unfolds, Bitget's response and the broader implications for the industry will be closely watched, highlighting the ongoing challenges of securing digital assets.

Bitget first disclosed the breach on September 30 with reports indicating the attackers exploited a zero-day vulnerability in a third-party security product according to BleepingComputer. The theft itself, although substantial, is not an isolated incident; numerous similar breaches have occurred in recent history where exchanges have faced significant financial losses due to security vulnerabilities. These events, often linked to the exploitation of zero-day vulnerabilities, serve as a stark reminder of the sophistication of modern cyber threats. The breach at Bitget also brings to light the importance of rapid incident response and the immediate steps taken by affected organizations to mitigate such risks.

Bitget faced a significant challenge in responding to this breach effectively. The discovery and disclosure of the breach on September 30 allowed the exchange to initiate its incident response procedures, including isolating affected systems and notifying users. By addressing both immediate threats and long-term vulnerabilities, Bitget aims to rebuild trust within the cryptocurrency community and prevent similar incidents in the future.

What happened

Bitget, a cryptocurrency exchange, disclosed today that attackers exploited a zero-day vulnerability in third-party security products to steal $387.5 million.

Bitget stated that the attackers leveraged a flaw to obtain high-level internal credentials, which they then used to issue fraudulent withdrawal commands to Bitget’s wallet system.

  • On September 24, 2026, the attackers executed the fraudulent withdrawals, enabling them to move the funds out.
  • The attack vector was traced to a third-party security solution used by Bitget, which had a previously undiscovered vulnerability.
  • According to BleepingComputer, the flaw allowed the attackers to bypass Bitget's security measures completely undetected.

After the incident, Bitget issued a statement confirming the breach and the amount stolen. The company assured that it is working with security experts to conduct a thorough investigation and implement new security measures.

Bitget reported that the attack exploited a product flaw that had gone undetected until the incident occurred. The company is collaborating with cybersecurity firms to patch the vulnerability and prevent similar attacks.

The third-party provider whose product was exploited has stated that it is cooperating with Bitget to address the flaw.

Security analysts note that zero-day vulnerabilities are particularly dangerous because they are unknown to security software and patches. The specifics of the vulnerability have not been disclosed to avoid exacerbating the threat.

In an effort to mitigate the impact, Bitget has frozen affected accounts and has begun reaching out to users whose funds were compromised.

Why it matters For cryptocurrency exchanges and financial institutions using third-party security products, this incident highlights major operational risks. Bitget's exposure underscores how even reputable third-party vendors can harbour critical vulnerabilities that compromise entire systems. The attacker's ability to gain high-level internal credentials shows that exploiting a single flaw can lead to extensive data breaches and large-scale theft. Exchanges typically keep most of their assets in hot wallets, making them particularly vulnerable. The attack on Bitget demonstrates the urgent need for continuous monitoring and rapid response to security incidents. Exchanges must ensure their systems are secured by regularly updating and patching software. As noted by The Hacker News and BleepingComputer, this incident also highlights the importance of having multiple layers of defence against such attacks. When third-party systems are compromised, internal protocols must be robust enough to respond to the situation effectively. Third-party security products are widely used to streamline processes, but this convenience brings risks. Security protocols must be reevaluated and hardened where needed. Cryptocurrency businesses, in particular, must ensure rigorous security practices extend beyond their immediate systems to cover third-party vendors as well. The attack shows that any third-party provider must be audited for potential risks. In practical terms, businesses must invest in advanced security solutions that go beyond basic protections. Regular security audits and vulnerability assessments are essential. Employees training must include scenario-based practices for responding to incidents like those experienced by Bitget. Regular drills and simulated attacks can help teams react more effectively in real-time. Furthermore, cryptocurrency platforms must focus on real-time monitoring solutions that can quickly identify and respond to irregular activity. Implementing machine learning-based anomaly detection systems can help detect unusual patterns that might indicate a breach. This proactive approach can mitigate the damage from potential attacks. In summary, the Bitget breach serves as a harsh reminder that no system is entirely secure. The operational impact includes increased risk assessments and the necessity for enhanced security infrastructure. Continuous improvement in security protocols and real-time monitoring are not just recommendations but necessities in an environment where vulnerabilities are constantly evolving. A breach like Bitget's can significantly erode trust, financial loss, and operational disruptions. Ensuring robust security frameworks and proactive incident response measures should be an ongoing priority for anyone dealing with digital assets.

What to do

  • Immediately audit internal systems for any third-party tools in use in all your organizations.
  • Review supplier security standards: demand vendor accountability for all security breaches.
  • Regularly update third-party security products to minimize vulnerabilities.
  • Ensure multi-signature mechanisms or extra approval steps for high-value transactions.
  • Check if sensitive credentials are only used for low-risk operations.

2TI lens

Security breaches via third-party tools like Bitget's underscore the need for constant vigilance. When integrating third-party software, it's crucial to have detailed audit trails and clear escalation protocols. A Spatial Digital Agency approach would address these challenges by ensuring seamless integration of monitoring tools and a unified security framework across disparate systems and services.

Attackers exploited a zero-day flaw in third-party security products, leading to a breach and the theft of $387.5 million from Bitget’s systems in an attack reported by BleepingComputer on September 30, 2026.. A flaw in a third-party security product the exchange used enabled the attacker to steal $388 million, according to The Hacker News on September 28, 2026. During the attack that began on September 24, fraudulent withdrawal commands were sent to the exchange's wallet system.

Quick answers

How did the attackers gain access to Bitget's systems?

Attackers exploited a zero-day flaw in a third-party security product used by Bitget, allowing them to obtain high-level internal credentials.

How much money was stolen in the Bitget hack?

$388 million

What actions did the attacker take after gaining access?

The attacker sent fraudulent withdrawal commands to Bitget's wallet system.