Bitget, a major cryptocurrency exchange, announced on Monday that an attacker stole approximately $388 million by exploiting a vulnerability in a third-party security product used by the platform. The incident highlights significant risks associated with external software dependencies in the crypto industry.
According to the exchange, the attacker leveraged the flaw in the third-party tool to obtain high-level internal credentials. These privileged access keys allowed the individual to bypass standard security protocols and interact directly with Bitget's internal systems.
On September 24, the threat actor utilized the compromised credentials to issue fraudulent withdrawal commands to Bitget's wallet system. This action resulted in the unauthorized transfer of digital assets, totaling the reported $388 million loss.
The disclosure underscores the critical importance of supply chain security for financial institutions, particularly in the decentralized finance sector. By relying on external security products, exchanges may be exposed to vulnerabilities that are not immediately apparent within their own infrastructure.
Bitget’s statement serves as a reminder that even robust internal defenses can be circumvented if third-party components contain exploitable weaknesses. The company has not detailed the specific nature of the vulnerability or the name of the third-party vendor involved in the provided materials.
<small>Source: The Hacker News — read the original story there.</small>