Bitget Confirms Zero-Day Exploitation in $387.5 Million Cryptocurrency Theft
Investigation links attack to third-party security product vulnerability; customized attacker tool recovered

Key Takeaways
- Bitget confirmed a $387.5 million theft resulted from exploitation of a zero-day vulnerability in third-party security products.
- SlowMist's investigation identified malicious activity and recovered a customized attacker tool.
- The zero-day details, affected products, and threat actor attribution remain under investigation.
Related Security News

CISA Adds Actively Exploited FortiMail Zero-Day to Known Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, affecting Fortinet FortiMail, has a CVSS score of 9.8 and allows unauthenticated attackers to write arbitrary files on the underlying system. CISA's action follows reports of active exploitation in the wild prior to the catalog addition.

Bitget breach attributed to zero-day in third-party security products
Bitget confirmed that a cyber attack last week resulted in the theft of approximately $387.5 million. The exchange stated that the breach was facilitated by exploitation of a zero-day vulnerability in third-party security products integrated into its infrastructure. The incident was disclosed on September 30, 2026. Details regarding the specific vulnerability, affected products, and exploitation vector remain unconfirmed.



