Bitget Hot Wallets Hacked via Compromised Security Products
Crypto exchange Bitget faced a massive attack on its hot wallets in late September. The investigation, led by SlowMist, revealed that malicious activity was linked to two third-party security products before the asset theft.
The attackers exploited a zero-day vulnerability in one product and gained access to another system using an employee's credentials.
SlowMist found that the earliest detected malicious activity occurred on August 31 on one of Product A's nodes. The attacker then launched a stealth script within the service process, read an environment variable containing the database password, and connected to it.