Which third-party security system vulnerability is it—what third-party one??

According to all currently disclosed reports (including Bitget’s official live stream, SlowMist, and Mandiant’s investigation), Bitget has never publicly named the specific third-party security product vendor from the beginning.

All parties’ wording has only been along the lines of “a third-party security product”:
In the live stream, Bitget CEO Gracy Chen said they had “notified the relevant third-party vendor,” shared the vulnerability details, temporarily took down the affected functions pending a fix—but did not disclose the vendor’s name. SlowMist’s interim investigation report similarly only states that “a certain third-party product has a zero-day vulnerability,” without naming Bitget. Bitget stated that it will “write the complete technical details into an official security report” later, and as of now the full report has not been published.

So at this stage, this remains a puzzle within the industry—the vendor identity is either being withheld by Bitget for reasons of safety coordination/responsible disclosure, or it will be disclosed in subsequent official incident reports. If any more specific information becomes available after the report is released, I can help you look into it again.

#bitget热钱包被盗源于第三方安全系统漏洞