Third-party security failure precedes $388 million Bitget theft

Third-party security failure precedes $388 million Bitget theft. About three hundred eighty eight dollars million was stolen from Bitget after an attacker reportedly exploited a vulnerability in a third-party security product used by the exchange.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 29th, 2026.

About three hundred eighty eight dollars million was stolen from Bitget after an attacker reportedly exploited a vulnerability in a third-party security product used by the exchange. The attacker obtained high-level internal credentials through that product and then used them on September 24th to send fraudulent withdrawal commands to Bitget’s wallet system. The important point is that the attacker didn’t need to steal private keys directly. Compromising the systems that prepare, validate, or authorize transactions was enough to create a major financial loss.

This puts the trust model around security suppliers under pressure. Vendor reviews need to examine not only whether a product is secure, but also how deeply it can reach into transaction and wallet systems. Security teams should review privileged integrations, monitor high-value commands, and rotate credentials linked to the affected product. Strong key protection remains important, but it doesn’t remove risk from surrounding approval systems. A trusted control can become a high-impact access path. Organizations should review every third-party product with privileged transaction access and require independent approval for high-value withdrawal commands.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Third-party security failure precedes $388 million Bitget theft
Broadcast by