SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit
SlowMist has traced the initial malicious activity associated with the Bitget hack back to August 31, when an attacker exploited a zero-day vulnerability within a third-party security product, ultimately resulting in a $388 million theft. This date marks the beginning of the Bitget hack activity.
The attackers executed the theft from Bitget's hot wallets on September 24 (UTC), transferring assets to their controlled addresses across various blockchains. SlowMist's investigation identified malicious actions involving two distinct third-party security products and a wallet application host.
Table of content
Attacker's Exploitation Methods
According to a progress report from SlowMist, the attacker utilized a hidden script to gain access to the database of a product, designated “Product A” by SlowMist, after retrieving its password from an environment variable. Similar activity was subsequently detected on two additional nodes on September 23 and September 25. All reported dates and times are in UTC+8.
On September 25, the attacker also accessed the management platform of a second security product, referred to as “Product B” by SlowMist, by impersonating an internal employee. SlowMist reported that the attacker then attempted to inject system commands, modify server configurations, and upload malicious program files. SlowMist indicated that its investigation into the Bitget hack activity is ongoing, with continued examination of how the attacker moved between the compromised systems.
Withdrawal Process Manipulation
The security firm stated that it recovered a highly customized tool, which had been deleted, used to manipulate the wallet system's withdrawal process. This tool was designed to forge risk-control parameters, construct withdrawal requests, and initiate the withdrawal process.
SlowMist's on-chain verification pinpointed the earliest confirmed transfer to 2:31 am UTC+8 on September 25, when an attacker-controlled address received 93 TRX. This was followed 11 seconds later by 0.84 Ether on the Ethereum network. The compiled transfer records spanned approximately two hours and 52 minutes across multiple blockchains, concluding at 5:23 am on the same day.
The attacker also attempted to directly alter withdrawal records within the wallet database and trigger additional Bitcoin withdrawals. SlowMist noted that two fabricated BTC withdrawal orders entered processing but encountered errors. Following this, the attacker reviewed logs, checked order statuses, and made further attempts.
Bitget's Response and Recovery Efforts
In a September 25 update, Bitget confirmed that approximately $387.5 million had been transferred to attacker-controlled addresses across several networks.
Bitget CEO Gracy Chen later stated that the breach originated from a vulnerability in a third-party security product, which enabled the attacker to obtain “high-level internal credentials” and issue fraudulent withdrawal commands. She affirmed that Bitget's private keys and cold wallets remained uncompromised.
Bitget is continuing efforts to recover the stolen assets. Chen expressed limited optimism regarding the full recovery of the approximately $388 million lost, referencing the limited recovery from a previous hack as a comparative point.