$388M Bitget Hack Linked to Zero-Day Exploit on August 31
Bitget, a major cryptocurrency exchange, suffered a $388 million hack on September 24 (UTC), with malicious activity linked to the attack dating back to August 31 when an attacker exploited a zero-day vulnerability in an external security product.
Slowest Mist, a blockchain security firm, published a progress report detailing their investigation into the hack. According to the report, the attacker used a custom tool to spoof risk control parameters and execute fraudulent withdrawals from Bitget's hot wallets.
The exchange's CEO, Gracy Chen, confirmed that the exploit originated from a vulnerability in an external security product, allowing the attacker to obtain high-level internal credentials and issue withdrawal commands. Chen expressed pessimism about recovering the full amount of funds, citing the limited outcome following the Bybit hack in 2025 as a reference.
SlowMist also recovered a deleted tool designed to manipulate the withdrawal process of Bitget's wallet system. The on-chain verification placed the first confirmed transfer at 2:31 am UTC+8 on September 25, when an address controlled by the attacker received assets across multiple blockchains.