Home › Intelligence › Brief
BREACH BRIEF🔴 Critical Breach

Bitget Confirms Third‑Party Zero‑Day Exploited in $387.5M Cryptocurrency Theft

Cryptocurrency exchange Bitget confirmed that attackers stole $387.5 million by exploiting a zero‑day vulnerability in a third‑party security product. The breach highlights the systemic risk of supply‑chain flaws and the need for robust vendor oversight in trust‑and‑control programs.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 thehackernews.com
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Bitget Confirms Third‑Party Zero‑Day Exploited in $387.5M Cryptocurrency Theft

What Happened — Bitget disclosed that attackers stole $387.5 million by exploiting a zero‑day vulnerability in a third‑party security product used by the exchange. The breach was uncovered through a joint investigation with the security firm SlowMist, which also recovered a custom tool used by the threat actors.

Why It Matters for Trust & Control Assurance

  • The incident is a textbook case of a supply‑chain control gap: a missing assurance process around third‑party security tooling enabled a massive asset loss.
  • Continuous vendor‑risk monitoring and documented evidence of due‑diligence are the exact controls a control‑assurance program should provide to detect and remediate such gaps before exploitation.
  • Mapping the third‑party risk control to a single VCF objective (vendor oversight) simultaneously satisfies requirements across NIST CSF 2.0, ISO 27001, and other frameworks, delivering a unified trust signal.

Who Is Affected – Cryptocurrency exchanges, digital‑asset custodians, and their customers; any organization that relies on third‑party security solutions for critical operations.

Recommended Actions

  • Inventory all third‑party security products and assess their patch‑management and vulnerability‑disclosure processes.
  • Integrate continuous monitoring of vendor security posture into your control‑assurance workflow, capturing evidence for audit readiness.
  • Update incident‑response playbooks to include supply‑chain compromise scenarios and conduct tabletop exercises.
  • Require vendors to provide proof of timely remediation for identified flaws and maintain that evidence in a centralized Trust Center.

Technical Notes – The attack leveraged a previously unknown (zero‑day) flaw in a security‑product component, allowing the adversary to bypass authentication and execute unauthorized transactions on the exchange’s hot‑wallet infrastructure. No public CVE has been assigned yet; the vulnerability is under coordinated disclosure. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/10/bitget-confirms-third-party-zero-day.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →