On September 30, Cointelegraph reported that SlowMist's investigation revealed that the earliest malicious activity related to the theft of $388 million from Bitget can be traced back to August 31, when attackers exploited a zero-day vulnerability in a third-party security product. The funds were stolen from Bitget's hot wallet and transferred to a multi-chain address controlled by the attackers on September 24 (UTC). The attack involved two third-party security products and a wallet application host: the attackers used hidden scripts to read the database of 'Product A' and accessed the management platform of 'Product B' as internal employees. SlowMist stated that it has recovered the custom tools used by the attackers to manipulate the withdrawal process. Bitget CEO Gracy Chen indicated that the vulnerability originated from a third-party security product, and the private keys and cold wallets were not compromised.
All Comments