⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

September 28, 2026

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M Swati KhandelwalSep 28, 2026Vulnerability / Cybercrime The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most customer funds in offline cold wallets and use hot and warm wallets to process withdrawals. Transfers from those wallets must still be approved before they are signed. The stolen funds came from part of Bitget's hot and warm wallets, and its cold wallets were not…