Cryptocurrency exchange Bitget has revealed that the attackers who stole $387.5 million last week got in by exploiting a zero-day flaw in third-party security products. The Bitget zero-day in third-party security products is a pointed reminder that the tools a company buys to defend itself can also become the way in.

This post sticks to what Bitget has disclosed and what is known so far, then looks at what it means for people who rely on VPNs, gateways, and other security software.

How the Bitget breach unfolded

According to Bitget's disclosure, the attackers breached its systems after exploiting a previously unknown flaw, a zero-day, in third-party security products. A zero-day is a vulnerability that is being exploited before the vendor has a fix available, which means defenders have no patch to apply at the time of the attack.

The result was a theft of $387.5 million from the exchange. Bitget made its disclosure about a week after the theft took place, so the public picture is still developing and details may change as investigations continue.

For additional technical context, blockchain security firm SlowMist has published findings that tie malicious activity to Aug. 31 and describe how attackers later manipulated withdrawal systems. You can read our coverage in SlowMist Traces Bitget Hack to Aug. 31 Zero-Day Activity.

Why third-party security tools are a systemic risk

Security products sit in privileged positions. Gateways, remote-access tools, and monitoring software often see sensitive traffic, hold credentials, and have broad access to internal systems. That makes them attractive targets: one flaw in a widely used product can open the door to many organizations at once.

This is the core tension of the Bitget case. A company can run its own infrastructure carefully and still be exposed through software it does not control. When the flaw is a zero-day, even a company with a strong patching routine has little it can do in the moment, because there is nothing yet to install.

It also shows why layered defenses matter. If one product fails, other controls such as network segmentation, strict access limits, and monitoring for unusual activity can limit how far an intruder gets. Our weekly roundup, NetScaler Zero-Day VPN Security Flaws Exploited, Bitget Hit, looks at how attackers keep finding ways around the defenses organizations put in place.

What the incident means for VPN and security tool users

The Bitget case involved an exchange, but the lesson carries over to any VPN, gateway, or security stack. These products are meant to reduce risk, yet they are software, and software has flaws. A VPN or remote-access appliance is a trusted entry point, so a vulnerability in one deserves the same attention as any other critical system.

What This Means For You

If you are an everyday user, you cannot patch a service provider's internal systems. What you can do is reduce the damage if a service you use is compromised:

  • Treat security tools as part of your attack surface, not as a guarantee of safety.
  • Keep your own software, including VPN clients and routers, updated.
  • Use unique passwords and multi-factor authentication on accounts, especially financial ones.
  • Be cautious with unsolicited messages after a major breach. Reports from social media suggest affected users may be receiving offers of crypto recovery help, which are a common follow-on scam pattern. Treat such offers skeptically.

If you manage systems for a team or business, inventory which security and remote-access products you run, and know who is responsible for monitoring their advisories.

How to judge a vendor's vulnerability disclosure record

No vendor is free of flaws, so how a company handles them is a better signal than a claim of perfection. When evaluating a security product or provider, consider:

  • Does the vendor publish security advisories? Clear, regular notices suggest an active process.
  • How quickly are patches released after a flaw is reported or exploited? Look for a track record rather than a single event.
  • Is the communication plain and specific? Good advisories say what is affected, what to do, and what is still unknown.
  • Is there a way to report vulnerabilities? A public contact or disclosure program shows the vendor expects to hear about problems.
  • Do they acknowledge past incidents openly? Transparency after a problem is generally healthier than silence.

None of these guarantees safety, but together they help you compare vendors on evidence instead of marketing.

Key takeaways

The Bitget zero-day in third-party security products shows that protection tools can be the weakest link when a flaw is exploited before a fix exists. Review which security products and remote-access tools you rely on, apply updates promptly, and follow vendor advisories so you hear about problems early. For more context, read our NetScaler zero-day roundup and the SlowMist investigation into the Bitget hack.