1 min read

Earliest Bitget Attack Activity Traced to Aug. 31

The interim investigation found suspected intrusions across third-party security systems and wallet infrastructure before verified asset transfers began Sept. 25.

Mentioned assets
Open equipment cabinet and loose network cable in a quiet corridor / TokenPost.ai
Open equipment cabinet and loose network cable in a quiet corridor / TokenPost.ai

The earliest suspected malicious activity in the Bitget security incident occurred Aug. 31, indicating attackers may have entered parts of the exchange’s supporting infrastructure weeks before verified asset transfers began.

A node server tied to a third-party security product was affected by a zero-day vulnerability on Aug. 31. A hidden script running under the service process attempted to access database credentials, environment variables and the database. Similar activity appeared on two other nodes Sept. 23 and Sept. 25.

In the early hours of Sept. 25, attackers allegedly used an internal employee account to access a second security product’s management platform. They repeatedly inserted system commands into task parameters, attempted to write malicious files and uploaded malware in stages through a Web execution function.

Investigators recovered a customized tool designed for wallet withdrawals. The tool could forge withdrawal parameters, build withdrawal requests and call the withdrawal process. It began running at 1:49 a.m. ET (05:49 UTC), while the first verified transfer occurred at 2:31 a.m. ET (06:31 UTC), when an attacker-controlled address received 93 TRX followed 11 seconds later by 0.84 ETH.

Asset transfers continued across multiple blockchain networks until 5:23 a.m. ET (09:23 UTC), a period of about two hours and 52 minutes. The investigation remained underway as of Sept. 29, with the full intrusion path and final loss still unresolved.

Loading…