Bitget Confirms Zero-Day in Third-Party Security Tools
🔐 Bitget confirmed attackers exploited a zero-day vulnerability in third-party security products to steal $387.5 million from its hot and warm wallets, according to a SlowMist investigation. The breach, disclosed on September 24, 2026, allowed attackers to obtain high-level credentials, bypass risk controls, and initiate fraudulent withdrawals across 11 blockchains. Bitget disabled the affected functionality and notified the vendor while freezing some assets.
