0x2ed166b82ed1…2ed166b5
SlowMist traces Bitget hack to August 31 zero-day exploit
Blockchain security firm SlowMist traced activity from a recent Bitget theft back to an August 31 zero-day exploit, identifying malicious operations that began weeks before the exchange disclosed the incident publicly.

Outputs
SlowMist traced Bitget theft activity to a zero-day exploit dated August 31.
Malicious activity began weeks before the exchange disclosed the theft publicly.
The attacker combined an undisclosed vulnerability, two security products and a custom withdrawal tool.
SlowMist's post-mortem does not name a threat actor.
Bitget faces a multi-week remediation push across affected integration points.
Blockchain security firm SlowMist has traced activity from a recent Bitget theft back to a zero-day exploit dated August 31, identifying malicious operations that began weeks before the exchange publicly disclosed the incident.
The firm's reconstruction places the earliest flagged on-chain activity on August 31, weeks before the theft surfaced on Bitget. The SlowMist team worked backward from the drain itself to the originating vulnerability, mapping a chain of transactions that ultimately pulled funds out of a Bitget-controlled wallet.
What did SlowMist actually find?
According to the security firm's write-up, the attacker combined three components to move funds off the platform:
- A zero-day vulnerability in code Bitget had not previously patched
- Two security products the attacker folded into the operation
- A custom withdrawal tool assembled to automate fund movements
The post-mortem does not name a threat actor. SlowMist did not respond to a request for comment outside Asian business hours.
How does the timeline reshape the Bitget incident?
The August 31 anchor pushes the intrusion window back considerably. Until SlowMist's analysis, public reporting on the Bitget incident clustered around a tighter, post-detection frame. The weeks-long head start gave the attacker time to stage infrastructure, validate tooling and rehearse the pipeline before any defensive response.
The operational tempo — pre-positioning, test transactions, then a coordinated drain — matches the pattern SlowMist and rival firms have documented across other centralized exchange compromises over the past two years. In each case, attackers have staged weeks of quiet access before moving funds.
That rhythm matters because dollar exposure grows with every additional day an attacker holds a foothold inside an exchange environment. Hot-wallet balances fluctuate, but the structural access — credentials, API keys, operational know-how — does not.
What technical details matter for other exchanges?
The reliance on a zero-day, rather than phishing or an insider leak, narrows the threat model considerably. Zero-days against exchange code require either a bought vulnerability from a private broker or an in-house research capability, both of which concentrate this class of attack among a small set of well-funded operators.
The integration of two security products into an exploit chain is a relatively novel escalation tactic. Defenders typically audit internally developed code, not the configuration of vendor-supplied packages. An attacker routing withdrawals through security infrastructure can blend activity into a stream of legitimate-looking transactions, complicating automated monitoring.
For peer venues, the operational lessons are concrete: audit every dependency, even signed ones; correlate withdrawal tooling against known customer environments; and shorten the gap between code change and production deployment.
What happens next?
Bitget faces a multi-week remediation push as it reviews every integration point touched during the compromise window. SlowMist's tracing data will shape how peer exchanges reconstruct their own incident playbooks and will likely feed into the exchange's eventual public disclosure.
Centralized venues will spend the coming weeks re-running their dependency audits. Regulators in major digital-asset jurisdictions have signaled that post-mortem cooperation and timely disclosure will factor into licensing reviews going forward, raising the operational stakes for any exchange that delays a similar investigation.
The full SlowMist report, including transaction hashes and a timeline graphic, is available on the firm's public research channel.
via github.com (Original)