1 min read

SlowMist Links Bitget Theft to Zero-Day Flaw and Custom Tool

The Sept. 25 attack lasted nearly three hours across multiple blockchains and later involved attempts to alter withdrawal records.

Mentioned assets
Locked access panel outside an empty operations room / TokenPost.ai
Locked access panel outside an empty operations room / TokenPost.ai

SlowMist linked Bitget’s Sept. 25 hot-wallet theft to a zero-day vulnerability in a third-party security product and a custom tool built to process withdrawals.

The attack also involved wallet application hosts and unauthorized access to the third-party product’s management platform through an internal employee identity, SlowMist said. Investigators obtained the tool used to interact with the wallet system’s withdrawal logic.

On-chain activity began Sept. 25 and continued for about two hours and 52 minutes across multiple blockchains. Afterward, the attackers attempted to modify withdrawal records and trigger additional Bitcoin (BTC) withdrawals.

The investigation is continuing, with the remaining focus on how the attackers moved laterally between the affected systems.

Loading…