Bitget Confirms Zero-Day Exploit Behind $387.5 Million Crypto Theft
Bitget, a cryptocurrency exchange, has confirmed that a zero-day vulnerability in a third-party security product was behind the theft of $387.5 million. The exchange cited findings from SlowMist's ongoing investigation into unauthorized wallet withdrawals.
The attack occurred on September 25, 2022, and impacted 11 blockchains, including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. The affected assets include XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, and TIA.
Bitget stated that attackers exploited the flaw to obtain high-level internal credentials and used those credentials to issue fraudulent withdrawal commands to the wallet system. The exchange described the resulting movements as 'abnormal transfers that bypassed existing risk controls.'
The investigation also found that a customized tool tailored to the wallet system's withdrawal logic was recovered by SlowMist, which began executing cryptocurrency theft at 01:49 a.m on September 25, 2022.