In a significant security breach, cryptocurrency exchange Bitget announced that an attacker exploited a vulnerability in a third-party security product, resulting in the theft of approximately $388 million. The attacker gained access to high-level internal credentials, which enabled them to issue fraudulent withdrawal commands from Bitget's wallet system on September 24. This incident underscores the potential risks associated with relying on third-party security solutions, emphasizing the need for thorough vetting and continuous monitoring of external tools and products used within the cybersecurity infrastructure.
For businesses, this breach serves as a critical reminder to assess their own dependencies on third-party services and the associated risks. Organizations must adopt a proactive approach to cybersecurity by implementing robust risk management practices, including regular security audits and vulnerability assessments of all third-party products. As the cybersecurity landscape continues to evolve, it is imperative for businesses to understand that vulnerabilities can arise not only from their own systems but also from external partners, making comprehensive security strategies crucial in safeguarding sensitive assets.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html)*