Attacker Exploits Third‑Party Security Product Flaw to Steal $388 M from Bitget Exchange
What Happened — An attacker leveraged a vulnerability in a third‑party security solution deployed by cryptocurrency exchange Bitget. The flaw granted the threat actor high‑level internal credentials, which were then used on September 24 to issue fraudulent withdrawal commands and siphon roughly $388 million.
Why It Matters for Trust & Control Assurance
- This incident illustrates the risk of insufficient third‑party risk oversight – a control area that continuous assurance programs are built to monitor and evidence.
- Demonstrable, up‑to‑date vendor assessments and real‑time monitoring of third‑party security controls provide the defensible audit trail needed to show due diligence.
- Mapping third‑party security evidence to a unified control framework (e.g., NIST CSF 2.0) helps organizations prove they have addressed the “Identify/Protect” objectives tied to supply‑chain risk.
Who Is Affected – Cryptocurrency exchanges, fintech platforms, and any organization that relies on external security products to protect high‑value assets.
Recommended Actions
- Initiate a formal third‑party risk review of all security‑product contracts; verify that vendors maintain a current vulnerability‑management program.
- Deploy continuous monitoring tools that collect and retain evidence of vendor control effectiveness for audit readiness.
- Re‑evaluate privileged‑access policies and enforce strict separation between vendor‑managed components and internal credential stores. Source: https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
Technical Notes – The attacker exploited an unpatched vulnerability in a third‑party security product (specific CVE not disclosed). The breach resulted in credential compromise and unauthorized wallet withdrawals. No customer data was reported as exposed. Source: https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html