SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit
SlowMist says the earliest malicious activity linked to Bitget’s $388 million theft dates back to Aug. 31, when an attacker exploited a zero-day vulnerability in a third-party security product. For PSPs and exchanges, the interesting part is not just the loss size: the attack chain ran through third-party security tools, internal credentials and a wallet application host.
- According to a SlowMist progress report, the attacker first used a hidden script to access the database of what SlowMist called “Product A,” after retrieving its password from an environment variable. The company later detected similar activity on two other nodes on Sept. 23 and Sept. 25. The dates and times in the report are in UTC+8.
- SlowMist said the attacker also accessed the management platform of a second security product, “Product B,” on Sept. 25 using an internal employee’s identity. From there, the attacker attempted to inject system commands, alter server configurations and upload malicious program files.
- The security company said it recovered a deleted, highly customized tool used to manipulate the wallet system’s withdrawal process. The tool forged risk-control parameters, constructed withdrawal requests and invoked the withdrawal process, which is exactly the kind of internal workflow abuse high-risk operators worry about when controls sit inside the same trust boundary as the wallet logic.
- SlowMist’s onchain verification found the earliest transfer verified to date at 2:31 am UTC+8 on Sept. 25, when an attacker-controlled address received 93 TRX, followed 11 seconds later by 0.84 Ether on Ethereum. The compiled transfer records covered about two hours and 52 minutes across multiple blockchains, ending at 5:23 am that day.
- The attacker also tried to modify withdrawal records directly in the wallet database and trigger additional Bitcoin withdrawals. SlowMist said two fabricated BTC withdrawal orders entered processing but returned errors, after which the attacker reviewed logs, checked order status and made further attempts. SlowMist said its investigation remains ongoing and that it is still examining how the attacker moved between the affected systems.
In a Sept. 25 update, Bitget said about $387.5 million was transferred to attacker-controlled addresses across several networks. Bitget CEO Gracy Chen later told Cointelegraph that the breach stemmed from a vulnerability in a third-party security product that allowed the attacker to obtain “high-level internal credentials” and issue fraudulent withdrawal commands; she said Bitget’s private keys and cold wallets were not compromised. Bitget is still trying to recover the stolen assets, and Chen said she was “not very optimistic” about fully recovering the roughly $388 million lost.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!