SlowMist says Bitget theft traces back to Aug. 31 and involved a third-party zero-day flaw

SlowMist says Bitget theft traces back to Aug. 31 and involved a third-party zero-day flaw

N
News Editor
2026-09-30 05:09:00
Blockchain security firm SlowMist said in a preliminary investigation that the Bitget hot wallet theft disclosed on Sept. 25 can be traced back to malicious activity as early as Aug. 31. The probe, conducted at Bitget’s request, found signs of attacks involving a specific third-party security product, the host running a wallet application, and a highly customized withdrawal tool used by the attacker. According to the report, an unauthorized party accessed the management platform of the third-party product on Sept. 25 while posing as an internal employee. SlowMist also said it identified and obtained a custom withdrawal tool designed to interact with the wallet system’s withdrawal logic. On-chain activity began at 02:31 on Sept. 25 and involved transfers across multiple blockchains over roughly 2 hours and 52 minutes. The report added that the attacker later attempted to tamper with withdrawal records and trigger additional BTC withdrawals. The findings released so far are described as preliminary as of Sept. 29.

Blockchain security firm SlowMist said it has released a preliminary investigation report into the Sept. 25 Bitget hot wallet theft after being commissioned by the exchange.

As of Sept. 29, the investigation found malicious activity involving a specific third-party security product, the host of the wallet application, and a highly customized withdrawal tool used by the attacker.

Preliminary findings

SlowMist listed several key findings in the report:

  • The earliest malicious activity can be traced to Aug. 31, when a zero-day vulnerability in a third-party product was exploited.
  • On Sept. 25, someone posing as an internal employee gained unauthorized access to the management platform of that third-party product.
  • Investigators identified and obtained a customized withdrawal tool designed to interact with the wallet system’s withdrawal logic.
  • On-chain activity started at 02:31 on Sept. 25, involved transfers across multiple blockchains, and lasted about 2 hours and 52 minutes.
  • The attacker later attempted to tamper with withdrawal records and trigger additional BTC withdrawals.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.