Bitget loses $387.5 million after third-party security breach
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, October 1st, 2026.
Cryptocurrency exchange Bitget lost three hundred eighty seven point five dollars million after attackers reached its wallet environment through third-party security products. Two separate investigations concluded that zero-day weaknesses in two security appliances were used to gain privileged access. The attackers placed a web shell on one appliance, moved laterally into a production wallet job server, and deployed malware along with a custom withdrawal tool. Available logs placed the earliest malicious activity on August 31st, before the theft occurred on September 25th.
The case shows how a security product can become a route into the systems it’s supposed to protect. Persistent access and lateral movement gave the attackers time to reach financially critical infrastructure before the final transfer. Leaders should ensure that third-party security appliances have clear ownership, monitoring, and incident-response plans, just like other privileged systems. Defenders should watch their behavior, restrict how far they can reach into the network, and protect secrets stored in environment variables and connected databases. The larger risk is placing too much trust in tools that have broad privileges but limited monitoring. Inventory privileged security appliances, restrict their access, and monitor them for unexpected scripts, shells, and lateral movement.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.