Cosine: Bitget attacker breached third-party security products before moving laterally into wallet systems, no private key leakage found
Odaily News: Cosine disclosed the interim investigation reports by SlowMist and Google Cloud's Mandiant on the Bitget hot wallet breach. Both reports indicate that the attackers first compromised systems related to third-party security products, then moved laterally into Bitget's wallet business environment.
SlowMist's investigation revealed that one of the third-party security product nodes had a zero-day vulnerability, with related malicious activity traced back to as early as August 31. On September 25, the attackers also used an internal employee identity to access the management platform of another third-party security product and used highly customized withdrawal tools to interact with the wallet system's withdrawal logic. Mandiant stated that after gaining persistent access through third-party security devices, the attackers moved laterally to production wallet task servers and deployed malicious programs.
Mandiant also stated that no evidence of Bitget private key leakage has been found so far, and cold wallets were not affected. Both security teams are continuing to investigate the specific intrusion paths the attackers took between the relevant systems.
