Crypto exchange Bitget confirmed Wednesday that attackers stole $387.5 million after exploiting a zero-day vulnerability in third-party security software used to protect its infrastructure. The breach, among the largest crypto heists of the year, was flagged in part by blockchain forensics firm SlowMist, which continues to trace the stolen funds. Bitget has not named the vendor whose product was compromised, but the incident underscores a recurring theme in 2026: attackers are increasingly targeting the security tools meant to defend networks rather than the networks themselves.
The Bitget breach lands amid one of the most intense weeks for exploited vulnerabilities and data theft this year, with actively exploited zero-days hitting Citrix NetScaler, Cisco SD-WAN Manager, and MikroTik RouterOS, alongside breaches at Labcorp's debt collection partner, Renfe, and the Dutch Institute for Vulnerability Disclosure. Taken together, the events paint a picture of an attack surface that is both widening and accelerating, with criminal groups moving faster from disclosure to exploitation and, increasingly, using AI tools to help them do it. For enterprises and consumers alike, the Bitget incident is a stark reminder that even well-resourced, security-conscious organizations remain exposed through the vendors and tools they trust.
A $387.5 Million Breach Rooted in Trusted Software
Bitget disclosed on Wednesday that attackers had siphoned $387.5 million from the exchange by exploiting a previously unknown flaw in third-party security software the company relied on to safeguard its systems. The company has not publicly identified the vendor involved, but it confirmed that the breach was first flagged through ongoing investigative work by blockchain forensics firm SlowMist, which has been tracking the stolen assets as they move across wallets and exchanges. Bitget said the incident is still under active investigation, and it has not ruled out further disclosures as the scope of the compromise becomes clearer.
The sheer scale of the theft places it among the largest cryptocurrency breaches of 2026, and it adds to a troubling pattern in which security products themselves become the point of failure. Rather than attacking Bitget's core trading infrastructure directly, the attackers appear to have found a weakness in the software designed to protect it, a tactic that has become increasingly common as threat actors recognize that security tooling often carries broad, trusted access across an organization's environment. That access, once compromised, can offer a far more efficient path to high-value targets than attacking hardened systems head-on.
A Week Defined by Actively Exploited Zero-Days
The Bitget breach did not occur in isolation. It capped a week in which security teams were already stretched thin by a wave of actively exploited vulnerabilities across enterprise infrastructure. Citrix NetScaler zero-days were used to drop web shells, steal configuration data, deploy tunneling malware, and move laterally inside victim networks, with SecurityWeek reporting that government and finance organizations were targeted over a multi-week campaign. BleepingComputer separately detailed exploitation of CVE-2026-88772, which attackers used to gain root access and harvest credentials.
Cisco, meanwhile, patched a critical zero-day in its Catalyst SD-WAN Manager, tracked as CVE-2026-76504, that was being actively exploited to escalate privileges to administrator level. CISA issued a warning about a critical MikroTik RouterOS vulnerability capable of enabling remote code execution or denial-of-service conditions, while WatchGuard released patches addressing fifteen separate bugs in its Fireware OS covering code execution, denial-of-service, authorization, and path traversal issues. TeamViewer also urged customers to patch high-severity flaws in its client and host software, and Chrome and Firefox shipped updates fixing more than 100 vulnerabilities combined, some severe enough to permit remote code execution or sandbox escape.
Breaches Beyond Crypto: Labcorp, Renfe, and DIVD
The financial sector was not the only target this week. A breach at a debt collection agency working with Labcorp exposed the personal data of more than 27.5 million people, including Social Security numbers and payment card details, making it one of the largest healthcare-adjacent data exposures reported in recent months. Spanish rail operator Renfe disclosed a separate cybersecurity incident that compromised user data, adding transportation infrastructure to the list of sectors hit this week.
In a notable twist, the Dutch Institute for Vulnerability Disclosure, an organization dedicated to coordinating responsible disclosure of security flaws, revealed that its own network had been breached through a chain of two zero-day vulnerabilities in Zammad, an open-source ticketing system. Separately, researchers found that more than 543,000 credentials exposed in public GitHub repositories remained valid as of July, despite platform protections designed to prevent accidental leaks, highlighting how persistent credential exposure continues to undermine even well-established security hygiene practices.
Security Tools as the New Attack Surface
The common thread linking Bitget's losses to the broader wave of exploitation this week is the targeting of infrastructure that organizations implicitly trust. Security software, network appliances, and ticketing systems all share a common vulnerability: they typically require elevated privileges or broad network access to function, making them high-value targets when a flaw is discovered. When attackers compromise these tools, they often inherit the very permissions meant to keep adversaries out.
This dynamic has pushed vendors into an increasingly urgent patch cycle, evidenced by the fifteen bugs addressed in WatchGuard's Fireware OS update and the emergency fixes issued by Citrix and Cisco. For enterprises, the lesson is that vendor risk management and rapid patch deployment are no longer optional hygiene steps but frontline defenses against financially devastating breaches like the one Bitget now faces.
The attackers didn't need to break Bitget's own defenses. They found a crack in the software meant to protect it, and that crack cost the company nearly $400 million before anyone caught it.
A Threat Landscape Moving Faster Than Defenses
Google's Threat Intelligence Group has tracked a rise in zero-day exploitation this year, averaging 11 incidents per month in 2026 compared to 8 per month in 2025, with a notable spike to 22 in August. Zero-days accounted for 62 percent of all exploited vulnerabilities between January and August, underscoring how quickly attackers are weaponizing previously unknown flaws once they surface. That trend, combined with incidents like the Bitget breach, suggests defenders are contending with both a faster-moving threat landscape and adversaries increasingly willing to target the security layer itself.
For Bitget, the immediate priority is containment, recovery, and transparency with affected users, while SlowMist continues tracing the stolen funds across blockchain networks. For the broader industry, the breach serves as a costly case study in why vendor security assessments, rapid patching, and zero-trust architectures need to extend to the tools organizations rely on for protection, not just the systems those tools are meant to defend.
Sources
- https://ciso.economictimes.indiatimes.com/news
- https://www.reuters.com/technology/cybersecurity/
- https://thehackernews.com/
- https://www.securityweek.com/
- https://www.bleepingcomputer.com/
- https://www.wired.com/category/security/
- https://x.com/The_Cyber_News
- https://thecyberwire.com/
- https://www.cybersecuritydive.com/
- https://news.crunchbase.com/sections/cybersecurity/
- https://cyberscoop.com/
- https://www.politico.com/cybersecurity-news-updates-analysis
- https://cyberscoop.com/news/threats/
- https://www.cnbc.com/cybersecurity/












Leave a Comment