Hit The Hacker News: Bitget confirms approximately $387.5 million stolen; the investigation points to zero-day exploitation of two third-party security products—after attackers obtain high-privilege internal credentials, they use custom tools to forge risk-control parameters, bypassing the normal withdrawal process to move hot/warm wallet assets.

Reports from Mandiant and SlowMist say the earliest malicious activity dates back to August 31; on September 24, a large transfer was carried out. It affected around 11 chains, including Ethereum, XRPL, Zcash, and TRON. So far, Circle, Tether, NEAR Intents, and others have collectively frozen about $1.1 million, which is still relatively small compared with the overall amount.

Once the third-party security stack is breached, the exchange’s own hot-wallet process is likely to fall too—on the supply-chain front, things will probably get scrutinized even more going forward.

#Bitget #crypto security