Bitget Confirms Zero-Day Behind $387.5M Crypto Theft
Bitget says the $387.5 million theft last week came from a zero-day in an unnamed third-party security product. The CVE and vendor remain undisclosed as the investigation continues.

Cryptocurrency exchange Bitget has confirmed that attackers who stole $387.5 million last week did so by exploiting a zero-day vulnerability in a third-party security product. The exchange disclosed the attribution on October 1 but has not named the affected vendor, identified the CVE, or said whether a patch exists.
The confirmation adds a specific technical shape to what had been a broader incident timeline. Bitget originally disclosed the theft on September 25, and resumed withdrawals three days later after asserting that user funds were covered by its protection fund. At the time, the exchange attributed the attack to suspected North Korean threat actors, consistent with earlier reporting on the initial $351.6 million figure.
The zero-day claim is significant because it shifts the immediate remediation question away from Bitget’s own infrastructure and onto an unidentified security vendor. If the vulnerability is in a product used across multiple exchanges or financial platforms, the risk is not contained to Bitget.
What Bitget has confirmed
According to Bitget’s statement, the attackers exploited a previously unknown flaw in third-party security products. The exchange says the investigation is ongoing and has not provided the vendor name, a CVE identifier, or technical specifics about the vulnerability class. There is no public advisory from a third-party vendor matching this description as of publication.
Bitget has committed to sharing further details as the investigation concludes. That timeline is not specified.
What remains unknown
Several critical details are unresolved. The identity of the affected vendor is not public, so other organizations using the same product cannot assess whether they are exposed. No CVE has been filed or assigned, meaning there is no standard tracking mechanism for the vulnerability. Whether the third-party vendor has issued a patch is not confirmed. And the DPRK attribution, while consistent with prior incidents of this scale, has not been independently corroborated by CISA, the FBI, or another government agency as of this article.
The scale of the theft, $387.5 million, places this among the largest single crypto exchange incidents on record. DPRK-affiliated groups have been linked to multiple large-scale cryptocurrency thefts, including the Bybit and WazirX incidents in 2024 and 2025, but attribution of this incident specifically remains pending official confirmation.
What crypto platforms should do now
The unnamed third-party vendor status makes specific remediation guidance difficult. That is an uncomfortable position for any security team running production infrastructure.
The practical near-term actions are: audit which third-party security products have privileged access to your key management or transaction signing infrastructure, and verify that any such product has current vendor support and recent security advisories. If you are running a product with no recent security releases, that is a risk to address regardless of this incident. Contact vendors directly to ask about their vulnerability disclosure programs and any advisories in the pipeline.
If the vendor and CVE become public, the immediate question will be patch status and whether exploitation requires authentication or can be triggered remotely. Watch vendor advisory channels and CISA’s Known Exploited Vulnerabilities catalog for any update.
This article will be updated when attribution details or a vendor advisory becomes available.
Found this useful? Share it.


