SlowMist has published a preliminary investigation into the Bitget incident, saying the earliest malicious activity identified so far dates back to Aug. 31. The report, shared on social media by SlowMist founder Cos, says the attacker is suspected of compromising two third-party security products and a wallet business host, then using a highly customized withdrawal tool to move assets across multiple blockchains.
SlowMist said the investigation was still underway as of Sept. 29. It has not yet confirmed how the attacker moved across multiple systems.
Earliest traceable activity appeared on Aug. 31
According to the report, the earliest malicious activity was found on Aug. 31, when a node server tied to third-party security product A had a zero-day vulnerability. The attacker ran hidden scripts under a service process and attempted to read database passwords, environment variables, and connect to the database.
Similar hidden-script activity was later found on two other nodes on Sept. 23 and Sept. 25, suggesting the related service environment may already have been compromised before assets were moved out.
Suspected access to security product B's management platform on Sept. 25
SlowMist said that in the early hours of Sept. 25, the attacker likely entered the management platform of security product B by abusing an internal employee account. Starting at 00:07, the attacker repeatedly appended system commands to task parameters in an attempt to write malicious files.
The attacker then used the platform's web execution entry to submit code, trying to modify server configuration, write communication relay files, and upload and assemble malicious programs in batches.
Customized tool targeted wallet withdrawal logic
SlowMist said investigators recovered, from files deleted by the attacker, a customized tool developed for wallet withdrawal logic. The tool was designed to forge withdrawal parameters, construct withdrawal requests, and invoke the withdrawal process.
Host logs show the related malicious program began running at 01:49 on Sept. 25.
First verified outbound transfer occurred at 02:31 on Sept. 25
On-chain records show the first verified outbound transfer took place at 02:31 on Sept. 25. The attacker's address first received 93 TRX and then, 11 seconds later, 0.84 ETH.
The transfers continued until 05:23 that day, lasting about 2 hours and 52 minutes and involving multiple blockchain networks.
Further attempts were made after funds started leaving
After the outflow began, the attacker also tried to directly modify withdrawal records in the wallet database and invoke local withdrawal tasks, according to the report.
Logs also contain records showing two forged BTC orders failed after business processing. Those attempts took place after 05:22.
Attack path may have spanned several layers
The disclosure suggests the attack path may have covered third-party security services, a management platform, wallet hosts, and the withdrawal business process.
SlowMist has not disclosed who it believes was behind the attack. It also has not stated the final scale of losses or the scope of affected systems.

