Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Summary
Cryptocurrency exchange Bitget has confirmed that a recent $387.5 million theft was the result of attackers exploiting a zero-day vulnerability in third-party security products. An ongoing investigation by SlowMist identified the vulnerability and a customized tool used by the attackers.
IFF Assessment
The exploitation of a zero-day vulnerability in a third-party security product by attackers leading to a significant cryptocurrency theft represents a major loss for defenders and the affected platform.
Defender Context
This incident highlights the critical importance of thoroughly vetting third-party security products, as vulnerabilities in these solutions can have catastrophic downstream effects. Defenders must remain vigilant about supply chain risks and have robust incident response plans in place to address breaches originating from trusted vendors.