SlowMist said on Sept. 30 that Bitget had asked its security team to investigate the hot wallet asset theft that took place on Sept. 25. As of Sept. 29, the firm said its investigation had found that the attack involved a third-party security product, malicious activity on the wallet application host, and a custom withdrawal tool developed by the attacker.
According to SlowMist, the attacker used a zero-day vulnerability in a third-party product to carry out malicious actions, then used an internal employee identity on Sept. 25 to gain unauthorized access to the management platform of that third-party product. The attacker also obtained and used a customized tool designed around the wallet’s withdrawal logic.
SlowMist said on-chain activity began at 02:31 on Sept. 25 (UTC+8), and assets were moved across multiple blockchains over roughly 2 hours and 52 minutes. It added that the attacker later attempted to tamper with withdrawal records and triggered additional BTC withdrawals. The firm said it is still investigating how the attacker moved laterally between affected systems.
SlowMist said on Sept. 30 that Bitget had commissioned its security team to investigate the hot wallet asset theft that occurred on Sept. 25.
As of Sept. 29, SlowMist said the investigation had found that the incident involved a third-party security product, malicious activity on the wallet application host, and a custom withdrawal tool developed by the attacker.
Attack methods disclosed so far
According to the investigation, the attacker mainly carried out the operation through the following methods:
- using a zero-day vulnerability in a third-party product to perform malicious actions;
- using an internal employee identity on Sept. 25 to gain unauthorized access to the management platform of that third-party product;
- obtaining and using a customized withdrawal tool designed for the wallet’s withdrawal logic.
On-chain transfers and later actions
SlowMist said on-chain activity began at 02:31 on Sept. 25 (UTC+8). The attacker moved assets across multiple blockchains over about 2 hours and 52 minutes.
It added that the attacker later attempted to tamper with withdrawal records and triggered additional BTC withdrawals. SlowMist said it is still investigating how the attacker moved laterally between the affected systems.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.