SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit

Summary

SlowMist said the Bitget theft traces back to Aug. 31, when an attacker exploited a zero-day in a third-party security product and later moved through multiple systems tied to two security tools and a wallet-hosting environment. The attacker allegedly used stolen credentials and a hidden script to access databases, then gained access to another product’s management platform with an employee identity and tried to run commands, change server settings, and upload malicious files. SlowMist also recovered a custom withdrawal tool that forged risk controls and generated fraudulent withdrawal requests. Onchain data showed the first verified transfer at 2:31 a.m. UTC+8 on Sept. 25, with asset transfers across several blockchains lasting nearly three hours. The attacker also tried to alter withdrawal records and trigger extra Bitcoin withdrawals. Bitget said about $387.5 million was moved to attacker-controlled addresses. The company says private keys and cold wallets were not compromised and recovery efforts continue.