Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Summary

Cryptocurrency exchange Bitget has confirmed that a recent $387.5 million theft was the result of attackers exploiting a zero-day vulnerability in third-party security products. An ongoing investigation by SlowMist identified the vulnerability and a customized tool used by the attackers.

IFF Assessment

FOE

The exploitation of a zero-day vulnerability in a third-party security product by attackers leading to a significant cryptocurrency theft represents a major loss for defenders and the affected platform.

Defender Context

This incident highlights the critical importance of thoroughly vetting third-party security products, as vulnerabilities in these solutions can have catastrophic downstream effects. Defenders must remain vigilant about supply chain risks and have robust incident response plans in place to address breaches originating from trusted vendors.

Read Full Story →