Bitget Hacked for $387.5 Million via Zero-Day Flaw in Third-Party Security Products
Crypto exchange Bitget revealed that attackers exploited a zero-day flaw in third-party security products to steal $387.5 million from its systems.
The breach, which occurred on September 25, involved two separate investigations by blockchain security firm SlowMist and Google Cloud's cyber-defense arm Mandiant.
According to the reports, threat actors accessed Bitget's wallet environment after compromising two security appliances with zero-day exploits. They then dropped web shells on one of the hacked appliances and malware on the crypto exchange's production wallet job server.
The earliest malicious activity identified in the available logs dates back to August 31, when a service running on one of Product A's nodes was affected by a zero-day vulnerability.