Bitget Hackers Sat Inside Exchange for Nearly Four Weeks Before $388M Heist
The Bitget hackers gained access to the exchange's systems on August 31, nearly four weeks before they drained $388 million from it. A compromised server allowed them to run code inside the system, and a zero-day vulnerability gave them access.
The attackers used an internal employee's identity to enter the management platform of another vendor tool, 'Product B,' and made three attempts to inject system commands. They then executed a highly customized withdrawal tool that forged risk-control parameters and triggered withdrawals.
Over 2 hours and 52 minutes, the attackers transferred funds across seven chains, with $228 million leaving in just 18 minutes. The stolen assets were laundered through CoW Protocol and Chainflip, but other doors have been shut to prevent further movement of the funds.
Bitget's User Protection Fund, holding over $464 million, covers the loss, and withdrawals are coming back in stages, with Bitcoin first followed by Ether, USDT, and then all other assets.