Investigation Reveals Zero-Day Exploit in Bitget Hack
Written with artificial intelligence.

SlowMist has traced the $388 million theft from Bitget to a zero-day vulnerability exploited weeks prior to the incident, involving multiple security products and a custom withdrawal tool. The investigation is ongoing as Bitget seeks to recover the stolen assets.
Overview of the Incident
SlowMist has reported that the initial malicious activity linked to the $388 million theft from Bitget occurred on August 31. An attacker exploited a zero-day vulnerability in a third-party security product, which led to the eventual theft of funds from Bitget's hot wallets on September 24.
Details of the Exploit
The investigation revealed that the attacker utilized a hidden script to access a database related to what SlowMist refers to as "Product A," after obtaining its password from an environment variable. Additional malicious activities were reported on two other nodes on September 23 and September 25. Moreover, the attacker accessed a second security product, labeled as "Product B," using an internal employee's identity and attempted to manipulate server configurations.
Recovery Efforts
SlowMist recovered a specialized tool that had been deleted, which was used to alter the wallet system's withdrawal process. This tool was capable of forging risk-control parameters and constructing withdrawal requests. The earliest verified transfer of stolen funds occurred at 2:31 AM UTC+8 on September 25, with the attacker transferring 93 TRX and 0.84 Ether shortly after.
Current Status
Bitget's CEO, Gracy Chen, confirmed that the breach resulted from a vulnerability in a third-party product, allowing the attacker access to high-level internal credentials. Despite the significant theft, she stated that Bitget's private keys and cold wallets were not compromised. The exchange is working on recovering the stolen assets but has expressed doubt about the likelihood of full recovery, citing past incidents as a benchmark.
