NewsCryptoSlowMist Traces Bitget $388M Hack to Zero-Day Exploit in Third-Party Security Product

SlowMist Traces Bitget $388M Hack to Zero-Day Exploit in Third-Party Security Product

Author: Cointelegraph·

Key Takeaways

  • •SlowMist traced the earliest logged malicious activity in the Bitget breach to Aug. 31, more than three weeks before roughly $388 million was stolen from the exchange's hot wallets on Sept. 24.
  • •The attacker exploited a zero-day vulnerability in a third-party security product and later used an internal employee's identity to access the management platform of a second security product.
  • •Investigators recovered a deleted, highly customized tool that forged risk-control parameters to construct and trigger fraudulent withdrawal requests in an effort to bypass internal checks.
  • •The earliest verified onchain transfer occurred at 2:31 am UTC+8 on Sept. 25, when an attacker-controlled address received 93 TRX, followed 11 seconds later by 0.84 Ether, with transfers spanning nearly three hours across multiple blockchains.
  • •Bitget CEO Gracy Chen said the company's private keys and cold wallets were not compromised and expressed doubt about fully recovering the stolen funds, while Cointelegraph reported she suspects North Korea was behind the hack based on IP clues.
SlowMist Traces Bitget $388M Hack to Zero-Day Exploit in Third-Party Security Product

Blockchain security firm SlowMist has traced the earliest logged malicious activity linked to the theft of roughly $388 million from crypto exchange Bitget to Aug. 31, when an attacker exploited a zero-day vulnerability affecting a third-party security product. A zero-day is a software flaw unknown to its vendor at the time of exploitation, meaning no patch exists when it is first used.

The funds were stolen from Bitget's hot wallets on Sept. 24 (UTC) and transferred to addresses controlled by the attacker across several blockchains. Hot wallets are internet-connected wallets that exchanges use to process withdrawals, in contrast to offline cold storage. According to a SlowMist progress report, the investigation identified malicious activity involving two third-party security products and a wallet application host. All dates and times cited in the report are in UTC+8, and the timeline places the earliest logged activity more than three weeks before the theft.

The report states that the attacker used a hidden script to access the database of what SlowMist called “Product A” after retrieving its password from an environment variable. Similar activity was later detected on two other nodes on Sept. 23 and Sept. 25.

On Sept. 25, the attacker also accessed the management platform of a second security product, referred to as “Product B,” using an internal employee's identity. SlowMist said the attacker then attempted to inject system commands, alter server configurations and upload malicious program files. The firm added that its investigation remains ongoing and that it is still examining how the attacker moved between the affected systems. The findings highlight a supply-chain exposure for exchanges: third-party tools granted privileged access to core systems can themselves become the path in when they are compromised.

Attacker used custom withdrawal tool

SlowMist said it recovered a deleted, highly customized tool that had been used to manipulate the wallet system's withdrawal process. The tool forged risk-control parameters, constructed withdrawal requests and invoked the withdrawal process — a sequence that points to an attempt to bypass the internal checks that normally screen an exchange's outgoing transactions.

The firm's onchain verification found that the earliest transfer verified to date occurred at 2:31 am UTC+8 on Sept. 25, when an attacker-controlled address received 93 TRX, followed 11 seconds later by 0.84 Ether on Ethereum. The compiled transfer records spanned about two hours and 52 minutes across multiple blockchains, extending to 5:23 am that day.

The attacker also attempted to modify withdrawal records directly in the wallet database and to trigger additional Bitcoin withdrawals. SlowMist said two fabricated BTC withdrawal orders entered processing but returned errors, after which the attacker reviewed logs, checked order status and made further attempts.

Bitget response and recovery outlook

In a Sept. 25 update, Bitget said about $387.5 million had been transferred to attacker-controlled addresses across several networks.

Bitget CEO Gracy Chen later told Cointelegraph that the breach stemmed from a vulnerability in a third-party security product that allowed the attacker to obtain “high-level internal credentials” and issue fraudulent withdrawal commands. She said Bitget's private keys and cold wallets were not compromised.

Bitget is still working to recover the stolen assets. Speaking on Cointelegraph's Chain Reaction show, Chen said she was “not very optimistic” about fully recovering the roughly $388 million lost, pointing to the limited recovery from Bybit's 2025 hack — the largest theft from a crypto exchange on record — as a reference point. In related coverage, Cointelegraph reported that Chen suspects North Korea was behind the hack, citing IP clues. SlowMist has said its investigation remains ongoing, leaving the attacker's full path through Bitget's systems and the extent of asset recovery as the key open questions.

Source: Cointelegraph