$388M Bitget Hack Traced Back to Zero-Day Exploit on August 31
SlowMist has investigated a massive hack of Bitget's hot wallets on September 24, which saw $388 million stolen from various blockchains. The earliest logged malicious activity linked to the theft was traced back to August 31, when an attacker exploited a zero-day vulnerability affecting a third-party security product.
SlowMist identified two third-party security products and a wallet application host involved in the attack. On September 25, the attacker accessed the management platform of 'Product B' using an internal employee's identity, attempting to inject system commands, alter server configurations, and upload malicious program files.
The investigation found that the attacker used a custom withdrawal tool to manipulate the wallet system's withdrawal process, forging risk-control parameters, constructing withdrawal requests, and invoking the withdrawal process. Onchain verification revealed that the earliest transfer verified to date was on September 25 at 2:31 am UTC+8, when an attacker-controlled address received 93 TRX, followed by 0.84 Ether on Ethereum.
Bitget CEO Gracy Chen said she was 'not very optimistic' about fully recovering the roughly $388 million lost, citing the limited recovery from Bybit's 2025 hack as a reference point. SlowMist's investigation remains ongoing, and it is still examining how the attacker moved between the affected systems.