Bitget $388 million stolen case sees key disclosure: the hacker exploited a zero-day vulnerability in a third-party security product to gain access to the exchange’s internal critical management system, forged trades, and initiated withdrawals—no private keys were used throughout. Halborn’s review highlights the core issue: transactions can be tampered with before they are cryptographically signed on-chain, allowing attackers to bypass the "signature-as-authentication" defense. The lesson from what is the biggest security incident of the year is very direct: Web3’s security perimeter has long extended beyond smart contracts to off-chain operations—signature workflows, back-end systems, and vendor components; any weak link can pierce the entire defense. The independent audit report will be published within a week—worth a close read.

#Bitget #Web3安全 #cyberattack