Investigation Reveals Details of Bitget Hot Wallet Theft
- SlowMist’s investigation, initiated on September 25, linked the theft to two compromised third-party security products.
- A zero-day vulnerability in Product A was exploited on August 31, allowing unauthorized access to sensitive data.
- The attacker generated withdrawal requests using a purpose-built tool that spoofed risk controls, leading to asset outflows starting September 25.
- Initial transfers included assets such as 93 TRX and 0.84 ETH, with confirmed activity lasting nearly three hours.
- Attempts to modify withdrawal records in the wallet database were made but resulted in errors for fabricated bitcoin orders.
The ongoing investigation has not disclosed the total value of stolen assets or identified the attacker or specific vulnerabilities within Products A and B. SlowMist continues to analyze how the attacker navigated between compromised systems.
As of now, significant details remain undisclosed regarding the full impact of this incident, including specific affected tokens and overall asset loss.(Source)