Published Wednesday, September 30, 2026 at 05:41 AM PT

BLUF: Bitget cryptocurrency exchange has been hacked via an unpatched zero-day vulnerability in a third-party security product. Attack vector and scope remain unclear. UNCONFIRMED: extent of funds/data compromise; specific vulnerable product; timeline.
DETAILS:
- Bitget (major crypto exchange) exploitation confirmed via zero-day in third-party security software โ vendor not yet disclosed in available material
- Attack leveraged security product vulnerability (pattern consistent with recent breaches: PaperCut, Citrix NetScaler, SonicWall, Check Point)
- BleepingComputer reported; no official Bitget statement available in provided sources
- Status of patches, incident response, or customer notification UNCONFIRMED
IMPACT:
- Bitget users: unknown exposure (balances, KYC data, transaction history status unclear)
- Third-party security product customers: potential collateral risk if product is widely deployed
- Crypto ecosystem: reputational/confidence impact typical of exchange breaches
RECOMMENDED ACTIONS (pending confirmation):
- IF you operate/use Bitget: monitor official channels for incident disclosure and reset API keys/credentials
- IF you deploy the affected third-party security product: identify which product is implicated, check vendor advisories immediately
- Security teams: flag as zero-day supply-chain risk โ watch for patches or workarounds from the affected vendor
SOURCES:
- BleepingComputer (headline only; full article content not provided)
- Related context notes a separate $351.6M Bitget theft (date/connection to this incident unconfirmed)
STATUS: Monitoring. Full details (victim count, funds at risk, product identification, timeline) pending public disclosure or Bitget statement.
Recent high-severity events at publish time:

