Bitget Hack Tied to Zero-Day Exploit, Investigators Recover Custom Withdrawal Tool
SlowMist investigators have found evidence that a zero-day exploit on August 31 allowed hackers to gain access to Bitget's hot wallets. The attackers stole approximately $388 million from these wallets, transferring funds to addresses under their control across multiple blockchains.
The earliest logged malicious activity linked to the hack occurred on August 31, when an attacker exploited a zero-day vulnerability affecting a third-party security product called 'Product A.' The hackers then accessed the management platform of another security product, dubbed 'Product B,' using an internal employee's identity on September 25.
The attackers used a custom withdrawal tool to manipulate the wallet system's withdrawal process, forging risk-control parameters and constructing withdrawal requests. SlowMist recovered this deleted tool during their investigation.
Onchain verification revealed that the earliest transfer verified to date occurred at 2:31 am UTC+8 on September 25, when an attacker-controlled address received 93 TRX, followed by 0.84 Ether on Ethereum.