Zero‑Day in Third‑Party Security Appliances Enables $387 M Theft from Bitget Crypto Exchange
What Happened – Attackers exploited a zero‑day vulnerability in two third‑party security appliances used by Bitget. They installed web shells, moved laterally to the production wallet job server, and deployed a custom withdrawal tool that siphoned $387.5 million across multiple blockchain networks.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of insufficient oversight of third‑party security products – a core scenario continuous control‑assurance programs aim to detect and document.
- Highlights the need for real‑time evidence of vendor risk monitoring, patch management, and privileged‑access controls to maintain a defensible audit trail.
- Shows how a single unpatched component can compromise critical financial assets, underscoring the importance of integrated third‑party risk management.
Who Is Affected – Cryptocurrency exchanges, fintech platforms, and any organization that relies on external security appliances for critical infrastructure.
Recommended Actions – Map this incident to your third‑party risk control objectives, implement continuous monitoring of vendor security updates, collect and retain evidence of patch status, and validate privileged‑access governance across all outsourced components. Source: https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
Technical Notes – The attackers leveraged a zero‑day flaw in “Product A” and “Product B” security appliances, dropped web shells, accessed environment variables containing database passwords, and used a custom withdrawal tool to move funds from hot and warm wallets. Source: https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/