SlowMist says earliest malicious activity in Bitget incident dates back to Aug. 31

SlowMist says earliest malicious activity in Bitget incident dates back to Aug. 31

N
News Editor
2026-09-30 04:58:55
SlowMist has released a preliminary investigation into the Bitget incident, saying the earliest malicious activity it has identified can be traced to Aug. 31. According to the report shared by SlowMist founder Cos on social media, the attacker is suspected of compromising two third-party security products and a wallet business host before using a customized withdrawal tool to move assets across multiple blockchains. The report says a node server tied to third-party security product A had a zero-day vulnerability on Aug. 31, when hidden scripts were run under a service process to read database passwords, environment variables, and connect to the database. Similar hidden-script activity was later found on two more nodes on Sept. 23 and Sept. 25. SlowMist also said the attacker likely entered the management platform of security product B in the early hours of Sept. 25 by abusing an internal employee account, then used task parameters and a web execution entry to write malicious files, alter server settings, and assemble malware. Host logs show the malicious program began running at 01:49 on Sept. 25. On-chain records show the first verified outbound transfer took place at 02:31, when the attacker address received 93 TRX and, 11 seconds later, 0.84 ETH. SlowMist said the investigation was still ongoing as of Sept. 29 and has not yet disclosed attribution, the final scale of losses, or the full scope of affected systems.

SlowMist has published a preliminary investigation into the Bitget incident, saying the earliest malicious activity identified so far dates back to Aug. 31. The report, shared on social media by SlowMist founder Cos, says the attacker is suspected of compromising two third-party security products and a wallet business host, then using a highly customized withdrawal tool to move assets across multiple blockchains.

SlowMist said the investigation was still underway as of Sept. 29. It has not yet confirmed how the attacker moved across multiple systems.

Earliest traceable activity appeared on Aug. 31

According to the report, the earliest malicious activity was found on Aug. 31, when a node server tied to third-party security product A had a zero-day vulnerability. The attacker ran hidden scripts under a service process and attempted to read database passwords, environment variables, and connect to the database.

Similar hidden-script activity was later found on two other nodes on Sept. 23 and Sept. 25, suggesting the related service environment may already have been compromised before assets were moved out.

Suspected access to security product B's management platform on Sept. 25

SlowMist said that in the early hours of Sept. 25, the attacker likely entered the management platform of security product B by abusing an internal employee account. Starting at 00:07, the attacker repeatedly appended system commands to task parameters in an attempt to write malicious files.

The attacker then used the platform's web execution entry to submit code, trying to modify server configuration, write communication relay files, and upload and assemble malicious programs in batches.

Customized tool targeted wallet withdrawal logic

SlowMist said investigators recovered, from files deleted by the attacker, a customized tool developed for wallet withdrawal logic. The tool was designed to forge withdrawal parameters, construct withdrawal requests, and invoke the withdrawal process.

Host logs show the related malicious program began running at 01:49 on Sept. 25.

First verified outbound transfer occurred at 02:31 on Sept. 25

On-chain records show the first verified outbound transfer took place at 02:31 on Sept. 25. The attacker's address first received 93 TRX and then, 11 seconds later, 0.84 ETH.

The transfers continued until 05:23 that day, lasting about 2 hours and 52 minutes and involving multiple blockchain networks.

Further attempts were made after funds started leaving

After the outflow began, the attacker also tried to directly modify withdrawal records in the wallet database and invoke local withdrawal tasks, according to the report.

Logs also contain records showing two forged BTC orders failed after business processing. Those attempts took place after 05:22.

Attack path may have spanned several layers

The disclosure suggests the attack path may have covered third-party security services, a management platform, wallet hosts, and the withdrawal business process.

SlowMist has not disclosed who it believes was behind the attack. It also has not stated the final scale of losses or the scope of affected systems.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.