Bitget Crypto Exchange Hit by $388M Theft via Third-Party Security Flaw

Moyen · The Hacker News ·

En bref

  • Unidentified attacker targeted Bitget crypto exchange.
  • A flaw in a third-party security tool was exploited.
  • Elevated internal credentials were compromised.
  • Fraudulent withdrawal orders led to $388 million stolen.
  • Incident occurred on Monday, September 24; no CVE assigned.

On Monday, September 24, Bitget, a cryptocurrency exchange, experienced a security breach. An unidentified actor took advantage of a weakness in a security product provided by a third-party vendor. This allowed the attacker to obtain privileged internal credentials. With those credentials, the attacker sent commands to withdraw funds, resulting in $388 million being stolen.

The incident affected Bitget and its users. The exchange's wallet system was the target of the fraudulent withdrawals. The third-party security vendor's product served as the entry point. High-level internal credentials were compromised, giving the attacker significant access to internal systems.

This event highlights the risks associated with third-party security tools. A vulnerability in such a product can become a gateway for attackers. Cryptocurrency exchanges remain attractive targets due to the large amounts of money involved. The lack of a CVE identifier means defenders may not have a specific reference for patching.

The attack occurred on a Monday. The attacker remains unknown. The method involved exploiting a vulnerability, obtaining credentials, and issuing withdrawal commands. The third-party security vendor has not been named. The wallet system was the focus of the fraudulent activity.

What to watch: Monitor for updates from Bitget and the third-party vendor. Watch for attribution of the attack. Check for similar vulnerabilities in third-party security products. Review credential management and withdrawal authorization processes. Consider the supply chain implications for your own organization.

À faire maintenant

  1. Audit all third-party security tools for known vulnerabilities and apply patches immediately.
  2. Rotate all high-privilege credentials, especially those with access to wallet systems or financial transactions.
  3. Enforce multi-factor authentication and least privilege for all internal accounts.
  4. Monitor for anomalous withdrawal commands and set up alerts for large transactions.
  5. Review vendor risk management processes and demand security assurances from third-party providers.
  6. Conduct an incident response drill focused on credential compromise and unauthorized withdrawals.
  7. Implement network segmentation to limit lateral movement if credentials are stolen.

Source originale

The Hacker News

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber