SlowMist Traces Bitget Hack to Zero-Day
- SlowMist traced the earliest logged activity tied to Bitget’s $387.5 million hack to Aug. 31, nearly four weeks before the theft.
- A zero-day vulnerability in a third-party security product gave the attacker access to part of Bitget’s infrastructure.
- SlowMist is still examining how the attacker moved between those systems and reached Bitget’s wallet infrastructure.
SlowMist has traced the earliest logged activity tied to Bitget’s $387.5 million hack to Aug. 31, nearly four weeks before attackers began draining the exchange’s wallets on Sept. 24.
Investigators found that a zero-day vulnerability in a third-party security product gave the attacker access to part of Bitget’s infrastructure. The finding shows that affected systems had been compromised weeks before the theft.
SlowMist is still examining how the attacker moved between those systems and reached Bitget’s wallet infrastructure.
Aug. 31 Activity Exposed First Compromised Security Product
SlowMist identified the earliest malicious activity on one node of a third-party product it called “Product A.”
The attacker ran a hidden script, extracted a database password from an environment variable and used it to connect to the product’s database. Similar activity appeared on two other nodes on Sept. 23 and Sept. 25.
SlowMist said the findings show that parts of the affected service environment had been compromised before funds began leaving Bitget.
Attacker Later Reached Second Third-Party Security Platform
The investigation also found activity involving another third-party product, labeled “Product B.” On Sept. 25 in UTC+8 time, the attacker entered its management platform using an internal employee identity and attempted to inject system commands.
SlowMist also found changes to server configurations and malicious program files. The firm has not named either third-party vendor while the investigation remains active.
Custom Tool Forged Bitget Withdrawal Requests
Investigators recovered a deleted tool built to manipulate Bitget’s withdrawal process. The tool forged risk-control parameters, constructed withdrawal requests and triggered the wallet system to process them.
The first verified on-chain transfer involved 93 TRX, followed 11 seconds later by 0.84 ETH. The confirmed transfers continued for about two hours and 52 minutes across multiple networks. Two additional fabricated Bitcoin withdrawal orders returned errors.
Bitget Says Private Keys and Cold Wallets Were Unaffected
Bitget says the breach moved about $387.5 million across Ethereum and other EVM networks, XRP Ledger, Zcash and TRON.
The exchange says its private keys were not compromised, and its cold wallets were unaffected. Bitget has patched the underlying vulnerability and brought in SlowMist and Mandiant to continue the investigation.
The remaining work is focused on tracing stolen assets, mapping the attacker’s route through the affected systems and recovering funds where possible.