Key facts
- SlowMist traced the earliest malicious activity linked to Bitget's $388 million theft to August 31.
- The attacker exploited a zero-day vulnerability affecting a third-party security product.
- On September 25, the attacker accessed a second security product's management platform using an internal employee's identity.
- A custom withdrawal tool was recovered, used to manipulate the wallet system's withdrawal process.
- The earliest verified transfer occurred at 2:31 am UTC+8 on September 25.
- Bitget CEO Gracy Chen stated the breach stemmed from a third-party security product vulnerability.
SlowMist has traced the earliest logged malicious activity connected to Bitget's $388 million theft to August 31, when an attacker exploited a zero-day vulnerability in a third-party security product. The funds were stolen from Bitget's hot wallets on September 24.
According to a SlowMist progress report, the attacker used a hidden script to access the database of "Product A" after retrieving its password from an environment variable. Similar activity was detected on two other nodes on September 23 and September 25. The report's dates and times are in UTC+8.
On September 25, the attacker also accessed the management platform of a second security product, "Product B," using an internal employee’s identity. SlowMist stated the attacker then attempted to inject system commands, alter server configurations, and upload malicious program files.
SlowMist recovered a deleted, highly customized tool used to manipulate the wallet system’s withdrawal process. This tool forged risk-control parameters, constructed withdrawal requests, and invoked the withdrawal process. Onchain verification by SlowMist found the earliest transfer at 2:31 am UTC+8 on September 25, when an attacker-controlled address received 93 TRX, followed by 0.84 Ether on Ethereum. The compiled transfer records spanned about two hours and 52 minutes across multiple blockchains.
The attacker also attempted to modify withdrawal records directly in the wallet database and trigger additional Bitcoin withdrawals, but two fabricated BTC withdrawal orders returned errors. Bitget CEO Gracy Chen told Cointelegraph that the breach stemmed from a vulnerability in a third-party security product that allowed the attacker to obtain "high-level internal credentials" and issue fraudulent withdrawal commands. She confirmed that Bitget’s private keys and cold wallets were not compromised.