Back to all lessons
Awareness Lessons
last week

Zero-Day in Third-Party Tool Enables $387.5M Crypto Heist

Attackers — attributed to North Korean threat actors — exploited an unpatched zero-day vulnerability in a third-party security product integrated into Bitget's environment, ultimately stealing $387.5 million in cryptocurrency. Once inside, the attackers harvested internal credentials and deployed malicious tooling to bypass controls and authorize fraudulent withdrawals, demonstrating how a single weak link in the supply chain can cascade into catastrophic financial loss. This incident highlights the critical danger of implicitly trusting third-party vendors without continuous vetting of their security posture. Organizations handling high-value assets must treat every external dependency as a potential attack surface and enforce least-privilege access even for trusted tools. The fact that credential access led directly to unauthorized withdrawals also underscores the failure to layer compensating controls beyond perimeter defenses.

Tactical Insight

Immediate actions

  • Audit and revoke all credentials that were accessible to or managed by the compromised third-party product.
  • Isolate or disable the affected third-party tool until a verified patch or secure alternative is in place.
  • Engage a threat intelligence or IR firm to hunt for lateral movement and persistence mechanisms left by the attackers.

Long-term improvements

  • Enforce strict third-party vendor risk assessments, including contractual obligations for timely vulnerability disclosure and patching SLAs.
  • Apply least-privilege and just-in-time access principles so that no single credential or tool can authorize high-value withdrawals unilaterally.
  • Implement multi-party authorization (MPC) or hardware-based signing for all large cryptocurrency withdrawal transactions.

Detection measures

  • Deploy behavioral analytics and anomaly detection on withdrawal workflows to flag unusual transaction volumes or out-of-hours activity.
  • Continuously monitor third-party software components using a software bill of materials (SBOM) and subscribe to vendor security advisories for rapid zero-day awareness.
  • Establish a dedicated threat-hunting capability focused on nation-state TTPs, particularly those attributed to North Korean actors (e.g., MITRE ATT&CK Lazarus Group techniques).