SlowMist|Sep 30, 2026 04:03
@bitget has engaged SlowMist’s security team to investigate the September 25 hot wallet asset theft.
As of September 29, our investigation has identified malicious activity involving certain third-party security products and a wallet application host, as well as a highly customized withdrawal tool used by the attacker.
🔎 Key findings include:
1. Malicious activity on a certain third-party product involving exploitation of a zero-day vulnerability.
2. Unauthorized access to a certain third-party products management platform on September 25 using an internal employee identity.
3. Recovery of a customized withdrawal tool designed to interact with the wallet system’s withdrawal logic.
4. On-chain activity begins at 02:31 on September 25, with transfers across multiple blockchains over approximately 2 hours and 52 minutes.
5. Subsequent attempts to manipulate withdrawal records and trigger additional BTC withdrawals.
We are continuing to investigate how the attacker moved between the affected systems.
All date references are to UTC+8.
📄 Read the details of the investigation:
https://github.com/slowmist/Knowledge-Base/blob/master/open-report-V2/incident-response/SlowMist%20Investigation%20Progress%20Report%20-%20Bitget_en-us.pdf
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink