SlowMist traced activity related to the $388 million theft from Bitget back to a zero-day exploit on August 31 that affected a third-party security product. The company identified early traces of the attacker weeks before the funds were withdrawn, including the compromise of two security solutions and the use of a custom tool to manipulate the withdrawal process.
Funds withdrawn from hot wallets on September 24
The attackers withdrew funds from Bitget’s hot wallets on September 24 (UTC), transferring assets to addresses they controlled across multiple networks. During its investigation, SlowMist recorded activity involving two third-party security products and the wallet application host. All timestamps in the report are in UTC+8.
Access to “Product A” via hidden script and environment variable
According to SlowMist’s interim report, the attacker used a hidden script to obtain a password from an environment variable and gained access to the “Product A” database. Similar activity was later detected on two other nodes—on September 23 and 25.
Compromise of “Product B” using employee account
On September 25, the attacker accessed the management platform of the second security product (“Product B”) using the credentials of an internal employee. The attacker then attempted to execute system commands, change server configurations, and upload malicious files.
Custom tool forged risk parameters and withdrawal requests
SlowMist recovered a deleted, highly specialized tool that forged risk control parameters, created withdrawal requests, and initiated the withdrawal process. On-chain analysis confirmed the earliest transfer at 2:31 UTC+8 on September 25: the attacker’s address received 93 TRX, followed 11 seconds later by 0.84 ETH on the Ethereum network. Consolidated transfers continued for about 2 hours and 52 minutes, ending at 5:23 the same day. The attacker also attempted to directly alter withdrawal records in the wallet database and initiate additional BTC withdrawals; two forged requests entered processing but returned errors.
Bitget assessed losses and clarified the vulnerability
On September 25, Bitget reported that about $387.5 million had been transferred to attacker-controlled addresses across various networks. According to Bitget CEO Gracy Chen, the breach was possible due to a vulnerability in a third-party security product, which gave the attacker high-level internal credentials and allowed the sending of fraudulent withdrawal commands. She stated that private keys and cold wallets were not affected. The exchange continues efforts to recover the assets.
