0x193cba44193c…193cba41

ConfirmedSecurity527 vB166 sat/vB3 min decode

SlowMist Traces Bitget's $388M Theft to Aug. 31 Zero-Day Exploit

SlowMist traced Bitget's $388 million hot wallet theft to an Aug. 31 zero-day exploit of a third-party security product, recovering a custom withdrawal tool used by the attacker.

SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit - LCX Exchange
WitnessSlowMist traces Bitget hack activity to Aug. 31 zero-day exploit - LCX ExchangeAI-generated

Outputs

  1. SlowMist traced the earliest malicious activity behind Bitget's ~$388 million theft to an Aug. 31 zero-day exploit of a third-party security product.

  2. The earliest verified on-chain transfer was 93 TRX at 2:31 a.m. UTC+8 on Sept. 25, followed by 0.84 ETH on Ethereum 11 seconds later; transfers spanned about two hours and 52 minutes.

  3. Bitget CEO Gracy Chen said cold wallets and private keys were not compromised, but she is 'not very optimistic' about full recovery of the stolen funds.

SlowMist has traced the earliest logged malicious activity behind Bitget's $388 million theft to Aug. 31, when an attacker exploited a zero-day vulnerability in a third-party security product, according to a progress report published by the blockchain security firm.

The attacker drained Bitget's hot wallets on Sept. 24 (UTC), moving assets to attacker-controlled addresses across several blockchains. Bitget confirmed in a Sept. 25 update that roughly $387.5 million had been transferred across multiple networks. SlowMist's investigation identified malicious activity involving two third-party security products and a wallet application host.

The attacker first used a hidden script to access the database of what SlowMist labeled "Product A," after retrieving its password from an environment variable, the report states. Similar activity later appeared on two other nodes on Sept. 23 and Sept. 25. All dates and times in the SlowMist report are given in UTC+8.

On Sept. 25, the attacker accessed the management platform of a second security product, "Product B," using an internal employee's identity. SlowMist said the attacker then attempted to inject system commands, alter server configurations and upload malicious program files. The investigation remains ongoing, with SlowMist still examining how the attacker pivoted between the affected systems.

Custom withdrawal tool recovered

SlowMist recovered a deleted, highly customized tool used to manipulate the wallet system's withdrawal process. The tool forged risk-control parameters, constructed withdrawal requests and invoked the withdrawal process directly.

On-chain verification by SlowMist confirmed the earliest transfer to date at 2:31 a.m. UTC+8 on Sept. 25, when an attacker-controlled address received 93 TRX. Eleven seconds later, the same cluster received 0.84 Ether on Ethereum. The compiled transfer records span roughly two hours and 52 minutes across multiple blockchains, ending at 5:23 a.m. that day.

The attacker also attempted to modify withdrawal records directly in the wallet database and trigger additional Bitcoin withdrawals. Two fabricated BTC withdrawal orders entered processing but returned errors. After the failures, the attacker reviewed logs, checked order status and made further attempts, according to the report.

CEO points to third-party credentials

Bitget CEO Gracy Chen said the breach stemmed from a vulnerability in a third-party security product that allowed the attacker to obtain "high-level internal credentials" and issue fraudulent withdrawal commands. She confirmed that Bitget's private keys and cold wallets were not compromised.

Chen has separately suggested that North Korea may be behind the incident, citing IP evidence, though attribution has not been confirmed.

Recovery prospects remain limited. Speaking on Cointelegraph's Chain Reaction, Chen said she was "not very optimistic" about fully recovering the roughly $388 million lost, pointing to the partial recovery following Bybit's 2025 hack as a reference point. Bitget continues to pursue the stolen assets.

The SlowMist findings shift attention from the exchange's own key management to its third-party vendor stack — a supply-chain exposure that could prompt tighter audits of security product integrations across the industry. SlowMist says its investigation is ongoing, and further findings on the attacker's lateral movement between systems are expected as forensic work continues.

via Google News - Crypto Hack Exploit (Source)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles