AI Weekly Malaysia

Back to items Summaries

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

ID
29442
Status
summarized
Published
29 Sep 2026, 1:42 AM
Fetched
29 Sep 2026, 2:53 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.5
Created
29 Sep 2026, 2:55 AM
Tags
Audience
developerssaas_startup_founders

What happened

Bitget says an attacker stole about $388 million from its hot and warm wallets by exploiting a zero-day vulnerability in an unnamed third-party security product it used, which gave access to high-level internal credentials. On September 24 the attacker sent fraudulent withdrawal commands into wallet backend services, starting with two small test transfers at 18:31 UTC that stayed under Bitget's risk-control threshold, then larger transfers roughly 30 minutes later that the wallet system executed while bypassing risk controls. Bitget says cold wallets and private keys were unaffected, has isolated systems, revoked and reissued credentials, and disabled the affected functionality, but has not said whether the vendor has shipped a fix; CEO Gracy Chen described the incident in a livestream and interviews.

Why it matters

This is a crypto-exchange incident with no stated Malaysia angle and nothing here that changes what most Malaysian developers, database learners, or SaaS founders build this week. The one transferable detail is the detection design: two test transfers below Bitget's risk-control threshold raised no alert, and the real drain followed ~30 minutes later — if you operate any withdrawal or approval flow, that is a concrete argument for alerting on threshold-adjacent sequences and not just on absolute size. Beyond that, the article does not name the third-party product, the vendor, or a fix, so you cannot act on the supply-chain angle from this text alone.

Discussion angle

Bitget's risk controls passed two small test transfers and then let the large ones through 30 minutes later — worth debating whether amount-based thresholds are the wrong primitive, and what you would monitor instead if you ran withdrawal approvals.

Top