Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exploitation of Third-Party Zero-Day Flaw Leads to $387.5 Million Cryptocurrency Theft




A $387.5 million cryptocurrency theft has been attributed to the exploitation of a third-party zero-day flaw. The attack, which occurred on September 24, 2026, was carried out by North Korean threat actors who exploited a zero-day vulnerability in third-party security products to gain unauthorized access to the exchange's wallet system. The incident highlights the importance of robust security measures and the need for greater collaboration and information-sharing between security companies and exchanges.

  • Bitget, a cryptocurrency exchange, was hacked, resulting in $387.5 million worth of cryptocurrency theft.
  • The attackers exploited a zero-day flaw in third-party security products to gain unauthorized access to Bitget's wallet system.
  • The attackers used a bespoke tool to siphon assets and moved laterally into Bitget's wallet environment using compromised security appliances.
  • The attack is believed to have been carried out by North Korean threat actors, with connections to illicit cryptocurrency laundering.
  • The incident highlights the importance of robust security measures to prevent such attacks and the need for greater collaboration and information-sharing between security companies and exchanges.



  • In a shocking turn of events, Bitget, a prominent cryptocurrency exchange, has confirmed that a third-party zero-day flaw was exploited by attackers to steal $387.5 million worth of cryptocurrencies. The incident, which occurred on September 24, 2026, has been attributed to a sophisticated attack that leveraged a zero-day vulnerability in third-party security products to gain unauthorized access to Bitget's wallet system.

    According to the investigation findings from SlowMist, a blockchain security company, the attackers exploited the zero-day flaw to obtain high-level internal credentials and use them to issue fraudulent withdrawal commands to the wallet system. The attack also involved the use of a bespoke tool to siphon the assets, which was highly tailored to the wallet system's withdrawal logic.

    The investigation revealed that the attackers gained unauthorized access to certain third-party security appliances, which they used to move laterally into Bitget's wallet environment. The attackers also deployed a web shell onto the security appliance and established a Command-and-Control (C2) connection, which enabled them to distribute malicious packages and gain control over the wallet job server.

    Bitget has since notified the relevant third-party vendor and disabled the affected functionality pending completion of a fix. The incident has also prompted the exchange to halt all withdrawals temporarily.

    The attack is believed to have been carried out by North Korean threat actors, with Elliptic and TRM Labs uncovering wallet overlaps used to launder illicit proceeds obtained from previous hacks. The incident has highlighted the importance of robust security measures to prevent such attacks.

    In a statement, Bitget confirmed that the attackers exploited a zero-day flaw in third-party security products, which they used to gain unauthorized access to the exchange's wallet system. The company has since taken steps to mitigate the damage and improve its security measures.

    The incident has also sparked concern among the cryptocurrency community, with many exchanges and wallets taking steps to enhance their security measures in response to the attack.

    The exploitation of third-party zero-day flaws is a growing concern in the cybersecurity landscape, with many companies and organizations being targeted by sophisticated attackers. The incident highlights the importance of robust security measures, including the implementation of third-party security products and the regular testing of these products to identify vulnerabilities.

    In addition, the incident highlights the need for greater collaboration and information-sharing between security companies and exchanges to prevent such attacks.

    The cryptocurrency market is highly vulnerable to cybersecurity threats, and the exploitation of third-party zero-day flaws is just one of the many risks that exchanges and wallets face. The incident serves as a reminder of the importance of robust security measures and the need for greater collaboration and information-sharing between security companies and exchanges.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exploitation-of-Third-Party-Zero-Day-Flaw-Leads-to-3875-Million-Cryptocurrency-Theft-ehn.shtml

  • https://thehackernews.com/2026/10/bitget-confirms-third-party-zero-day.html

  • https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/

  • https://cybersecuritynews.com/bitget-backend-breach/


  • Published: Thu Oct 1 01:47:34 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us