Blockchain security firm SlowMist said its investigation into the Bitget hack traced suspicious activity back to Aug. 31, when attackers exploited a zero-day vulnerability in a third-party security product. According to the findings, the intruders later moved through two external security tools and a wallet application host before funds were withdrawn from Bitget hot wallets.

The reported theft unfolded on Sept. 25 after the attackers used a custom-built withdrawal tool that manipulated the exchange’s wallet workflow. Bitget CEO Gracy Chen said the incident did not compromise private keys or cold wallets, and attributed the breach to a flaw in a third-party security product that enabled the attackers to obtain internal credentials and send fraudulent withdrawal commands.

Earliest activity traced to late August

SlowMist said the earliest confirmed malicious activity connected to the attack dates to Aug. 31. The investigation identified a hidden script that accessed the database of what it referred to as “Product A,” a third-party security product, after obtaining a password from an environment variable.

Investigators said similar malicious behavior was observed again on Sept. 23 and Sept. 25. The broader incident path described by SlowMist involved two third-party security products as well as a wallet application host, suggesting the attackers moved through several connected systems before the theft was executed.

Second security tool reportedly used on Sept. 25

On Sept. 25, the attacker was also found to have entered the management platform of a second security product, labeled “Product B,” by using the identity of an internal employee, according to SlowMist’s report.

Once inside that platform, the attacker allegedly tried to inject commands, change configurations, and upload malicious files. The report did not state that all of those attempts succeeded, but it presented them as part of the sequence leading up to the unauthorized withdrawals.

Custom withdrawal tool used to forge checks

SlowMist said the attackers relied on a customized withdrawal tool to interfere with Bitget’s wallet withdrawal flow. The tool allegedly forged risk-control parameters and generated fraudulent withdrawal requests, allowing unauthorized transfers to be initiated from the exchange’s hot wallets.

Onchain verification cited in the report showed transfers starting at 2:31 am UTC+8 on Sept. 25 to an address controlled by the attacker. More transfers then followed across multiple blockchains for roughly two hours and 52 minutes, with the activity ending at about 5:23 am.

Investigators also said the attacker attempted to alter withdrawal records in the wallet database and to trigger additional Bitcoin withdrawals. Two fabricated BTC withdrawal orders were processed, but both reportedly ended in errors.

Bitget says cold wallets were unaffected

Bitget CEO Gracy Chen later said the breach was caused by a vulnerability in a third-party security product that let the attacker obtain internal credentials and issue fraudulent withdrawal commands. She added that private keys and cold wallets were not compromised.

Bitget is still trying to recover assets, according to the report. However, the outlook for recovery was described as limited, underscoring the difficulty of reclaiming funds once they have been moved through attacker-controlled addresses across several blockchains.

Source: cointelegraph.com