LOOK CRYPTO · DATA PIPELINE

Data collection status

Checking collection status…

← All news
CRYPTO NEWS

SlowMist Links Bitget Hack to August 31 Zero-Day Exploit

Cointelegraph · Ezra Reguerra

Security firm SlowMist traced the earliest malicious activity related to Bitget’s $388 million theft back to August 31, when an attacker exploited a zero-day vulnerability in a third-party security product. This breach enabled the attacker to infiltrate Bitget’s systems and steal funds from hot wallets on September 24. The investigation uncovered the use of a custom withdrawal manipulation tool and attempts to alter withdrawal records directly in the wallet database, highlighting the complexity of the attack.

Timeline and Attack Methods

According to SlowMist’s report, the attack began on August 31 with a hidden script accessing the database of “Product A,” a third-party security product, retrieving its password from an environment variable. Similar malicious activity was recorded on other nodes on September 23 and 25.

On September 25, the attacker gained access to the management platform of a second security product, dubbed “Product B,” impersonating an internal employee. Attempts were made to inject system commands, alter server configurations, and upload malicious software. The investigation remains ongoing to determine the exact lateral movement between systems.

Use of a Custom Withdrawal Manipulation Tool

SlowMist recovered a deleted, highly customized tool used to manipulate the wallet withdrawal process. This tool forged risk control parameters, constructed withdrawal requests, and invoked the withdrawal operation.

On-chain analysis revealed the earliest transfer at 2:31 am (UTC+8) on September 25, when an attacker-controlled address received 93 TRX, followed seconds later by 0.84 ETH on Ethereum. Transfers spanned nearly three hours across multiple blockchains.

The attacker also tried to directly modify withdrawal records in the wallet database and initiate additional Bitcoin withdrawals. Two fabricated BTC withdrawal orders entered processing but returned errors, after which the attacker reviewed logs, checked order statuses, and made further attempts.

Bitget’s Official Statements and Impact

By September 25, Bitget announced that approximately $387.5 million had been transferred to attacker-controlled addresses across multiple networks.

Bitget CEO Gracy Chen told Cointelegraph that the breach resulted from a vulnerability in a third-party security product. This flaw enabled the attacker to obtain “high-level internal credentials” and issue fraudulent withdrawal commands. Importantly, Bitget’s private keys and cold wallets were not compromised.

Bitget is still attempting to recover the stolen assets. Chen expressed pessimism about fully recuperating the roughly $388 million lost, referencing the limited recovery seen after Bybit’s 2025 hack as a comparison.

Why it matters

This investigation sheds light on the technical details behind one of the largest hacks on the Bitget crypto exchange, involving a loss of nearly $388 million. Understanding how the attack exploited a zero-day vulnerability in third-party security products highlights the critical importance of a comprehensive security approach. The use of a customized tool to bypass risk controls demonstrates the sophistication of modern attackers. Bitget’s claim that private keys and cold wallets remained uncompromised underscores the significant risk posed by software vulnerabilities rather than direct key breaches. The expressed pessimism about full asset recovery and related legal implications emphasize the scale of the loss and the inherent challenges of retrieving stolen crypto assets across blockchains.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗