Cryptocurrency exchange Bitget says attackers who stole $387.5 million last week gained access by exploiting a zero-day vulnerability in third-party security products. The company also says it is still investigating how the breach began and what additional systems may be affected.

Bitget attributes key findings to its ongoing work with SlowMist, which examined the incident and identified malicious activity involving external security tools used in the environment. According to these findings, the attacker leveraged a custom approach tied to the compromised third-party components. Bitget further reports that investigators recovered a customized tool used by the attacker, supporting the conclusion that the intrusion chain involved more than a direct compromise of Bitget’s own software.

Across the reports, the central agreed point is the linkage between the large-scale theft and a zero-day flaw present in third-party security products. The outlets differ mainly in how much detail they provide about the investigation status and the specific evidence described, but both present the third-party zero-day as the cause Bitget is currently confirming.