SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit

3 min read
SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Blockchain security firm SlowMist has traced the earliest activity behind Bitget's $388 million theft to a zero-day exploit used on Aug. 31, weeks before the Sept. 24 hot-wallet breach. The firm found the attacker infiltrated two third-party security products and used a custom tool to forge withdrawal requests.

SlowMist traced the earliest logged malicious activity tied to Bitget's $388 million theft to Aug. 31, when an attacker exploited a zero-day vulnerability in a third-party security product. Attackers then stole funds from Bitget's hot wallets on Sept. 24 UTC, moving assets to addresses they controlled across several blockchains.

Attacker moved through two security products

According to a SlowMist progress report, the attacker used a hidden script to access the database of what SlowMist called "Product A," after retrieving its password from an environment variable. Similar activity turned up on two other nodes on Sept. 23 and Sept. 25. On Sept. 25, the attacker also accessed the management platform of a second product, "Product B," using an internal employee's identity, then attempted to inject system commands, alter server configurations and upload malicious program files. SlowMist said its investigation remains ongoing as it examines how the attacker moved between the affected systems.

Custom tool forged withdrawal requests

SlowMist said it recovered a deleted, highly customized tool used to manipulate the wallet system's withdrawal process, which forged risk-control parameters, constructed withdrawal requests and invoked the withdrawal process itself. Onchain verification found the earliest confirmed transfer at 2:31 am UTC+8 on Sept. 25, when an attacker-controlled address received 93 TRX, followed 11 seconds later by 0.84 Ether on Ethereum. The compiled transfer records span about two hours and 52 minutes across multiple blockchains, extending to 5:23 am that day. The attacker also tried to modify withdrawal records directly in the wallet database and trigger additional Bitcoin withdrawals; two fabricated BTC withdrawal orders entered processing but returned errors, after which the attacker reviewed logs, checked order status and made further attempts.

Bitget still working to recover funds

In a Sept. 25 update, Bitget said about $387.5 million was transferred to attacker-controlled addresses across several networks. Bitget CEO Gracy Chen later told Cointelegraph that the breach stemmed from a vulnerability in a third-party security product that let the attacker obtain high-level internal credentials and issue fraudulent withdrawal commands, adding that Bitget's private keys and cold wallets were not compromised. Speaking on Cointelegraph's Chain Reaction, Chen said she was "not very optimistic" about fully recovering the roughly $388 million lost, pointing to the limited recovery from Bybit's 2025 hack as a reference point.

Source: Cointelegraph.com News

Trading involves risk.

Most traded markets

XAU / USD
+0.2% 4,190.56
BRENT
+2.23% 101.678
BTC / USD
-0.71% 83,746.7
EUR / USD
+0.13% 1.13569
USTEC
-0.35% 30,276.33
AAPL
-0.08% 329.70
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Crypto News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.