Bitget Confirms Third‑Party Zero‑Day Exploited in $387.5M Cryptocurrency Theft
What Happened — Bitget disclosed that attackers stole $387.5 million by exploiting a zero‑day vulnerability in a third‑party security product used by the exchange. The breach was uncovered through a joint investigation with the security firm SlowMist, which also recovered a custom tool used by the threat actors.
Why It Matters for Trust & Control Assurance
- The incident is a textbook case of a supply‑chain control gap: a missing assurance process around third‑party security tooling enabled a massive asset loss.
- Continuous vendor‑risk monitoring and documented evidence of due‑diligence are the exact controls a control‑assurance program should provide to detect and remediate such gaps before exploitation.
- Mapping the third‑party risk control to a single VCF objective (vendor oversight) simultaneously satisfies requirements across NIST CSF 2.0, ISO 27001, and other frameworks, delivering a unified trust signal.
Who Is Affected – Cryptocurrency exchanges, digital‑asset custodians, and their customers; any organization that relies on third‑party security solutions for critical operations.
Recommended Actions
- Inventory all third‑party security products and assess their patch‑management and vulnerability‑disclosure processes.
- Integrate continuous monitoring of vendor security posture into your control‑assurance workflow, capturing evidence for audit readiness.
- Update incident‑response playbooks to include supply‑chain compromise scenarios and conduct tabletop exercises.
- Require vendors to provide proof of timely remediation for identified flaws and maintain that evidence in a centralized Trust Center.
Technical Notes – The attack leveraged a previously unknown (zero‑day) flaw in a security‑product component, allowing the adversary to bypass authentication and execute unauthorized transactions on the exchange’s hot‑wallet infrastructure. No public CVE has been assigned yet; the vulnerability is under coordinated disclosure. Source: The Hacker News