Bitget Says Third-Party Security Appliance Zero-Days Enabled Wallet Breach

Security operations analysts monitoring protected financial systems

Written by

in

Cryptocurrency exchange Bitget says forensic investigators traced its September security incident to vulnerabilities in third-party security products. In an update citing work by Mandiant and SlowMist, the company said the compromise of those appliances ultimately enabled unauthorized access to its exchange wallet environment.

Investigators describe lateral movement

Reporting on the interim findings, BleepingComputer said the attacker obtained privileged access to third-party security appliances, deployed a web shell on one appliance, and established command-and-control access. The intruder then moved laterally toward a production wallet job server and deployed malicious components used in the theft. Bitget’s original incident notice said unauthorized transfers were detected on September 24 and that withdrawals were suspended while the company contained the incident.

Security appliances remain part of the attack surface

The findings underline the risk created when perimeter or monitoring products hold privileged access to production systems. Operators should include security appliances in vulnerability management, restrict management paths, monitor administrative activity, and segment wallet or transaction infrastructure from edge systems. Incident responders should also preserve appliance logs and validate whether credentials exposed during the initial compromise were reused elsewhere. Further security incident coverage is available in the SectechMedia Technology News archive. The investigation remains the authoritative source for the final attack sequence.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *