BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

SlowMist: Bitget hack involved a zero-day vulnerability in a third-party security product, attacker used custom withdrawal tool

Odaily News — SlowMist security team has disclosed preliminary investigation findings on the September 25 theft of assets from Bitget's hot wallet. The investigation found that the attack involved certain third-party security products and wallet application hosts, with a zero-day vulnerability present in one of the third-party products. The attacker also gained unauthorized access to a third-party product management platform by impersonating an internal employee.

SlowMist stated that the team has obtained the custom withdrawal tool used by the attacker to interact with the wallet system's withdrawal logic. On-chain attack activity began at 2:31 on September 25, lasted approximately 2 hours and 52 minutes, and involved multiple blockchains. The attacker subsequently attempted to tamper with withdrawal records and trigger additional BTC withdrawals. The team is still investigating how the attacker moved laterally between the affected systems.