Bitget Attack Began Weeks Before Asset Transfers
The investigation into the Bitget security incident has revealed that the earliest suspected malicious activity occurred on August 31. According to investigators, attackers may have entered parts of the exchange's supporting infrastructure weeks before verified asset transfers began.
A node server tied to a third-party security product was affected by a zero-day vulnerability on August 31. The hidden script running under the service process attempted to access database credentials, environment variables, and the database. Similar activity appeared on two other nodes on September 23 and September 25.
In the early hours of September 25, attackers allegedly used an internal employee account to access a second security product's management platform. They repeatedly inserted system commands into task parameters, attempted to write malicious files, and uploaded malware in stages through a Web execution function.
Investigators recovered a customized tool designed for wallet withdrawals. The tool could forge withdrawal parameters, build withdrawal requests, and call the withdrawal process. It began running at 1:49 a.m. ET (05:49 UTC), while the first verified transfer occurred at 2:31 a.m. ET (06:31 UTC). Asset transfers continued across multiple blockchain networks until 5:23 a.m. ET (09:23 UTC).
The investigation remained underway as of September 29, with the full intrusion path and final loss still unresolved.