Bitget Hack Traced to Zero-Day Exploit on August 31
Security firm SlowMist has uncovered new information about the recent $388 million hack of Bitget, tracing the earliest malicious activity to August 31st. On this day, an attacker exploited a zero-day vulnerability in a third-party security product to gain access to internal credentials.
The attack was not immediately successful, with no funds stolen until September 24th. Between September 23rd and 25th, the attacker accessed two third-party security products, using a hidden script to retrieve the password of 'Product A' from an environment variable.
On September 25th, the attacker accessed the management platform of another security product, 'Product B', using an internal employee's identity. The attack attempted to inject system commands and alter server configurations, but was unsuccessful in retrieving funds.
The attacker did manage to steal $387.5 million from Bitget's hot wallets on September 24th, transferring the assets to addresses they controlled across several blockchains. SlowMist has recovered a customized withdrawal tool used by the attackers, which forged risk-control parameters and constructed withdrawal requests.