Zero-Day Flaw Exposed in Bitget Theft
Bitget, a cryptocurrency exchange, suffered a hot wallet theft on September 25. The attack was linked to a zero-day vulnerability in a third-party security product and a custom tool used for withdrawals.
According to SlowMist, investigators found that the attackers gained unauthorized access to the third-party product's management platform through an internal employee identity. They also obtained the custom tool used to interact with the wallet system's withdrawal logic.
The on-chain activity lasted for approximately two hours and 52 minutes across multiple blockchains. Afterward, the attackers attempted to modify withdrawal records and trigger additional Bitcoin (BTC) withdrawals.