SlowMist Ties Bitget’s $388M Hack to Aug 31 Zero-Day Exploit

hacker slowmist bitget
Table of Contents

TL;DR:

  • SlowMist traced the malicious activity linked to the $388M theft at Bitget back to August 31, when a zero-day vulnerability was exploited.
  • The attacker used a custom tool to spoof risk control parameters and execute fraudulent withdrawals from the exchange’s hot wallets.
  • Bitget CEO Gracy Chen admitted that private keys were not compromised, but expressed pessimism about the possibility of recovering the funds.

The blockchain security firm SlowMist identified that the earliest malicious activity linked to the $388 million theft at Bitget dates back to August 31, 2026, when an attacker exploited a zero-day vulnerability in an external security product.

This finding is part of a progress report published by the company, which continues to investigate one of the largest hacks of the year in the crypto industry.

According to the report, the attacker used a hidden script to access the database of what SlowMist called “Product A“, obtaining its password from an environment variable. Similar activity was detected on two other nodes on September 23 and 25. The actual theft of funds occurred on September 24 (UTC), when assets were transferred from Bitget’s hot wallets to addresses controlled by the attacker across multiple blockchains.

Slowmist post

SlowMist Found a Custom Withdrawal Tool

On September 25, the attacker also accessed the management platform of a second security product —referred to as “Product B“— using the identity of an internal employee. From that access, they attempted to inject system commands, modify server configurations, and upload malicious files.

SlowMist also recovered a deleted, highly customized tool designed to manipulate the withdrawal process of the wallet system: the instrument spoofed risk control parameters, constructed withdrawal requests, and invoked the fund extraction process.

Exploit bitget

Transfers Executed in the Exploit

SlowMist’s onchain verification placed the first confirmed transfer at 2:31 am UTC+8 on September 25, when an address controlled by the attacker received 93 TRX, followed 11 seconds later by 0.84 ETH on the Ethereum network. The transfer log spanned approximately two hours and 52 minutes across multiple blockchains, ending at 5:23 am that day.

Bitget CEO Gracy Chen confirmed that the exploit originated from a vulnerability in an external security product that allowed the attacker to obtain high-level internal credentials and issue fraudulent withdrawal commands, while clarifying that the exchange’s private keys and cold wallets were not compromised.

In statements on Cointelegraph’s Chain Reaction program, Chen said she was “not very optimistic” about recovering the full amount of the funds, citing the limited outcome following the Bybit hack in 2025 as a reference.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews