PANews丨APP全面升级|Sep 30, 2026 07:07
SlowMist: Bitget hack traces back to August 31, involving a zero-day vulnerability in a third-party product
SlowMist was commissioned by Bitget to investigate the theft of assets from its hot wallet on September 25 and has released a preliminary investigation report. As of September 29, the investigation uncovered malicious activities involving specific third-party security products and wallet application hosts, as well as highly customized withdrawal tools used by the attackers.
Key findings include:
- The earliest malicious activity dates back to August 31, where a zero-day vulnerability in a third-party product was exploited;
- On September 25, someone accessed the third-party product management platform as an internal employee without authorization;
- A customized withdrawal tool was discovered, designed to interact with the withdrawal logic of the wallet system;
- On-chain activity began at 02:31 on September 25, involving transfers across multiple blockchains, lasting approximately 2 hours and 52 minutes;
- There was an attempt to tamper with withdrawal records and trigger additional BTC withdrawal operations afterward.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink