NG Solution Team
Cybersecurity

SlowMist Links Bitget Hack to Aug. 31 Zero-Day in Security Product

SlowMist traced the earliest logged malicious activity tied to the Bitget hack to Aug. 31, when an attacker exploited a zero-day vulnerability affecting a third-party security product, the security firm said. The attacker later stole funds from Bitget’s hot wallets on Sept. 24 (UTC), transferring assets to addresses they controlled across multiple blockchains.

SlowMist’s investigation identified malicious activity involving two third-party security products and a wallet application host. In its progress report, SlowMist said the attacker used a hidden script to access the database of what the company called “Product A” after retrieving its password from an environment variable. Similar activity on other nodes was detected on Sept. 23 and Sept. 25. The dates and times in the report are given in UTC+8.

On Sept. 25, the attacker also accessed the management platform of a second security product, labeled “Product B,” using an internal employee’s identity. SlowMist said the attacker then attempted to inject system commands, alter server configurations and upload malicious program files. The company said its investigation remains ongoing and that it is still examining how the attacker moved between the affected systems.

Bitget hack: zero-day exploited to reach security products

SlowMist said it recovered a deleted, highly customized tool used to manipulate the wallet system’s withdrawal process. The tool forged risk-control parameters, constructed withdrawal requests and invoked the withdrawal process. The security firm also found that the attacker tried to modify withdrawal records directly in the wallet database and to trigger additional Bitcoin withdrawals; two fabricated BTC withdrawal orders entered processing but returned errors, after which the attacker reviewed logs, checked order status and made further attempts.

SlowMist’s on-chain verification identified the earliest transfer to date at 2:31 a.m. UTC+8 on Sept. 25, when an attacker-controlled address received 93 TRX, followed 11 seconds later by 0.84 Ether on Ethereum. The compiled transfer records spanned about two hours and 52 minutes across multiple blockchains, extending to 5:23 a.m. that day.

In a Sept. 25 update, Bitget said about $387.5 million was transferred to attacker-controlled addresses across several networks. Bitget CEO Gracy Chen later said the breach stemmed from a vulnerability in a third-party security product that allowed the attacker to obtain “high-level internal credentials” and issue fraudulent withdrawal commands. She said Bitget’s private keys and cold wallets were not compromised.

Bitget is still trying to recover the stolen assets. Chen said she was “not very optimistic” about fully recovering the roughly $388 million lost, pointing to the limited recovery from Bybit’s 2025 hack as a reference point.

Related posts

Indian Railways Cybersecurity Alert After WhatsApp Web Malware

Jessica Williams

How Does ThreatCluster Reduce Security Alert Noise with Its New Platform?

Jessica Williams

C-Track breach: Thomson Reuters reports unauthorized access to files

Emily Brown

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy