Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
- ID
- 29442
- Status
- summarized
- Published
- 29 Sep 2026, 1:42 AM
- Fetched
- 29 Sep 2026, 2:53 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.5
- Created
- 29 Sep 2026, 2:55 AM
- Tags
- Audience
- developerssaas_startup_founders
What happened
Bitget says an attacker stole about $388 million from its hot and warm wallets by exploiting a zero-day vulnerability in an unnamed third-party security product it used, which gave access to high-level internal credentials. On September 24 the attacker sent fraudulent withdrawal commands into wallet backend services, starting with two small test transfers at 18:31 UTC that stayed under Bitget's risk-control threshold, then larger transfers roughly 30 minutes later that the wallet system executed while bypassing risk controls. Bitget says cold wallets and private keys were unaffected, has isolated systems, revoked and reissued credentials, and disabled the affected functionality, but has not said whether the vendor has shipped a fix; CEO Gracy Chen described the incident in a livestream and interviews.
Why it matters
This is a crypto-exchange incident with no stated Malaysia angle and nothing here that changes what most Malaysian developers, database learners, or SaaS founders build this week. The one transferable detail is the detection design: two test transfers below Bitget's risk-control threshold raised no alert, and the real drain followed ~30 minutes later — if you operate any withdrawal or approval flow, that is a concrete argument for alerting on threshold-adjacent sequences and not just on absolute size. Beyond that, the article does not name the third-party product, the vendor, or a fix, so you cannot act on the supply-chain angle from this text alone.
Discussion angle
Bitget's risk controls passed two small test transfers and then let the large ones through 30 minutes later — worth debating whether amount-based thresholds are the wrong primitive, and what you would monitor instead if you ran withdrawal approvals.