1 min read

Bitget Attackers Reached Wallet Systems Via Third-Party Security Products

Investigators found no evidence that Bitget private keys were exposed, while cold wallets were not affected.

Gloved hand reaches toward a security appliance behind locked access / TokenPost.ai
Gloved hand reaches toward a security appliance behind locked access / TokenPost.ai

Attackers targeting Bitget first breached a third-party security product before moving laterally into the exchange’s wallet environment, while investigators found no evidence that private keys were exposed.

The investigation found that one third-party security product node contained a zero-day vulnerability, with related malicious activity traceable to Aug. 31.

On Sept. 25, the attackers also used an internal employee identity to access the management platform of another third-party security product. They then used a customized withdrawal tool to interact with Bitget’s wallet-system withdrawal logic.

The attackers obtained persistent access through a third-party security device, moved into production servers handling wallet operations and deployed malicious software. The investigation found no evidence that Bitget private keys were leaked, and cold wallets were not affected.

Investigators are continuing to examine the precise path the attackers used between the affected systems.

Loading…