BTC
-
SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit
SlowMist has traced the initial malicious activity linked to the $388 million Bitget hack to August 31, when an attacker exploited a zero-day vulnerability in a third-party security product. The attackers stole funds from Bitget's hot wallets on September 24, transferring assets across multiple blockchains. SlowMist's investigation identified the use of a hidden script to access a database and later, the management platform of a second security product. Bitget's CEO indicated the breach stemmed from a third-party vulnerability that granted high-level internal credentials, but confirmed private keys and cold wallets were not compromised. Efforts to recover the stolen assets are ongoing.
2026-09-30