SlowMist Investigates $388 Million Bitget Hack Linked to Zero-Day Exploit
- The earliest malicious activity related to the Bitget hack was traced to Aug. 31, when a zero-day vulnerability was exploited.
- On Sept. 24, attackers stole approximately $388 million from Bitget’s hot wallets, transferring assets across multiple blockchains.
- SlowMist identified that the attacker used a custom withdrawal tool to manipulate the wallet system and issue fraudulent commands.
- The first verified transfer occurred at 2:31 am UTC+8 on Sept. 25, involving transfers of TRX and Ether to attacker-controlled addresses.
- Bitget CEO Gracy Chen stated that the breach resulted from vulnerabilities in third-party security products, but cold wallets remained secure.
The investigation by SlowMist is ongoing as they analyze how the attacker navigated between systems and manipulated withdrawal processes. The incident highlights vulnerabilities within third-party security solutions used by exchanges.
As of a Sept. update, around $387.5 million had been transferred to addresses controlled by attackers, raising concerns over asset recovery efforts following such significant losses.