Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Bitget $387.5M Hack: SlowMist and Mandiant Say Zero-Day Attack Began Weeks Before Theft

Attackers had access to Bitget’s infrastructure since August 31, weeks before the September 24 theft, and later used a custom tool to forge withdrawal orders.

Written By Dishita Malvania
Edited by Divya Mistry
Published 57 minutes ago·Updated 40 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Bitget $387.5M Hack: SlowMist and Mandiant Say Zero-Day Attack Began Weeks Before Theft

Attackers behind the $387.5 million Bitget hack had a foothold inside parts of the exchange’s infrastructure almost four weeks before any funds moved, according to interim forensic findings released on September 30 by blockchain security firm SlowMist and cybersecurity firm Mandiant. 

Both firms said the attacker did not steal private keys. Instead, the intruder compromised third-party security products, in one case through a zero-day vulnerability, moved into Bitget’s wallet environment and used a custom withdrawal tool to send transfers that the exchange’s own systems accepted as valid.

A zero-day vulnerability is a software flaw that is unknown to the vendor and has no available fix at the time it is exploited. Neither SlowMist nor Mandiant named the affected vendors, and Bitget has not named them either. Both firms described their findings as interim.

AI Summary
Show
Attackers accessed a third‑party product on August 31, establishing foothold weeks before any funds moved.
Unauthorized internal‑employee login occurred September 24, followed by custom withdrawal tool deployment and transfers starting 18:31 UTC.
On‑chain theft lasted about 2 hours 52 minutes, ending September 24 21:23 UTC, with subsequent failed withdrawal attempts.

Bitget, a Seychelles-based centralized cryptocurrency exchange, hired the two firms in the hours after its September 24 breach. The attack hit some of the exchange’s hot wallets, which stay connected to the internet to process routine withdrawals, and warm wallets, which sit between hot wallets and offline storage. Bitget’s cold wallets and its separately operated self-custody product, Bitget Wallet, were not affected, the exchange has said.

What SlowMist Found

SlowMist said Bitget commissioned it to investigate the hot wallet theft. Its English-language summary, current as of September 29 and posted on September 30, uses China Standard Time (UTC+8), eight hours ahead of Coordinated Universal Time (UTC). The firm listed five findings:

  • Malicious activity on a third-party product that exploited a zero-day vulnerability.
  • Unauthorized access on September 25 (UTC+8) to a third-party product’s management platform using an internal employee identity.
  • Recovery of a highly customized withdrawal tool built around the wallet system’s withdrawal logic.
  • On-chain transfers starting at 02:31 on September 25 (UTC+8) and running across multiple blockchains for about 2 hours and 52 minutes.
  • Later attempts to alter withdrawal records and trigger additional Bitcoin (BTC) withdrawals.

SlowMist said it is still establishing how the attacker moved between those systems.

A Timeline That Starts on August 31

A longer Chinese-language account from SlowMist co-founder Yu Xian, known online as Cos, adds detail that the English summary did not include. All times below are converted from UTC+8 to UTC.

The earliest malicious activity dates to August 31. On a node of a system Cos refers to only as “Product A,” the zero-day allowed the attacker to run a hidden script under the service process, attempt to read database passwords and environment variables, and connect to the database. Similar hidden-script activity appeared on two other nodes on September 23 and September 25 (UTC+8). SlowMist reads this as evidence that the environment was already compromised before funds left.

The attacker then entered a second system, “Product B,” using an internal employee identity. From about 16:07 UTC on September 24, task parameters were used to splice in system commands and attempt to write malicious files. Code submitted through a web execution interface then tried to change server configuration, place relay files and assemble malware in pieces. SlowMist recovered, from deleted files, a custom tool that forged withdrawal parameters and called Bitget’s withdrawal process. Malicious programs on the host started at about 17:49 UTC.

The first verified on-chain outflow came at 18:31 UTC: 93 TRX, the native token of the TRON blockchain, sent to an attacker address, followed 11 seconds later by 0.84 Ether (ETH). Transfers continued until 21:23 UTC. After funds began leaving, logs show attempts to edit withdrawal records in the wallet database and two forged BTC withdrawal orders that failed after 21:22 UTC.

The 18:31 UTC start matches the minute Bitget first said its systems detected unauthorized transfers on September 24.

What Mandiant Found

Mandiant, Google Cloud’s incident response and threat intelligence unit, released a parallel note through Bitget. It said the attacker gained unauthorized access to certain third-party security appliances, moved laterally into Bitget Exchange’s wallet environment, and obtained access to warm and hot wallets. Lateral movement refers to an intruder shifting from one compromised system to others inside the same network.

Mandiant, which is part of Google Cloud, has shared its findings into its investigation into Bitget's September 24 security incident.

The investigation found that the attacker gained unauthorised access to certain third-party security appliances, before moving laterally into…

— Bitget (@bitget) September 30, 2026

According to Cos’s summary of both reports, Mandiant found no evidence that Bitget’s private keys were leaked and confirmed that cold wallets were not affected. After establishing persistent access through the third-party devices, the attacker moved to production wallet task servers and deployed malware. Both firms said they are still mapping the exact path between systems.

Bitget’s Response

Bitget thanked SlowMist and said the firm had confirmed malicious activity on third-party security products, including a zero-day, and recovered the tool used for the unauthorized withdrawals. The exchange said the findings align with the attack path it previously shared and that it is now focusing on applying them and tightening controls. Bitget’s Chinese-language account posted the same message.

The forensic notes support what Bitget told users on September 28, when it reopened BTC withdrawals and said the attacker obtained high-level internal credentials through a vulnerability in a third-party security product. Until today, that account came only from Bitget itself.

How the Findings Fit the Record So Far

Bitget first put the loss at $351.6 million, then raised it to about $387.5 million on September 25 after adding Zcash (ZEC) and TRON transfers from the same attack window. It said the revision did not reflect a second breach and launched a 5% recovery bounty for frozen funds.

Blockchain security firm GoPlus Security had already concluded that the attacker made Bitget’s own signing system approve the transfers, with the largest wave of about $185 million moving in roughly one minute at 19:16 UTC on September 24. SlowMist’s recovered withdrawal tool offers the first independent evidence of how those forged instructions reached the signing process.

Bitget has kept to its phased withdrawal schedule, with Tether (USDT) due on September 30 and remaining tokens, fiat and peer-to-peer (P2P) services on October 2. The exchange says its User Protection Fund, which held more than $464 million at the time of the incident, covers the loss.

Laundering Continues

SlowMist’s on-chain tracking unit, MistTrack, has continued to follow the stolen funds. Cos said suspected operators are placing automated orders on CoW Protocol, a decentralized exchange aggregator, with recipient addresses pre-set to deposit contracts on Chainflip, a cross-chain swap network, before bridging into Bitcoin. 

He said Chainflip has tried to block some flows, but automated splitting across bridges is outpacing Anti-Money Laundering (AML) and Know Your Transaction (KYT) checks. Once funds reach Bitcoin, he said, CoinJoin, a technique that mixes multiple users’ transactions to obscure their origin, is being used.

Earlier, cross-chain protocol THORChain declined a request from Bitget Chief Executive Officer (CEO) Gracy Chen to refuse known attacker addresses, citing its permissionless design. On-chain investigator ZachXBT has also identified five people he says are laundering the funds for suspected North Korean operators.

Attribution to North Korea remains a working theory from Bitget, blockchain analytics firm Elliptic, and on-chain investigators. No government has issued a formal attribution.

What Remains Unanswered

Several questions remain open. The firms have not identified who developed the zero-day, which products “Product A” and “Product B” are, or how the internal employee identity was obtained or forged. It is also unclear how long persistent access lasted between August 31 and September 24, and how much of the stolen funds has been frozen compared with the amount already swapped into Bitcoin.

Bitget has said it expects to publish a fuller security report this week. SlowMist and Mandiant have both described their September 30 findings as interim.

Also Read: Metaplanet Says Warrant Chapter Is Closed After $220M Value Wipeout

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Kalshi Is Ending Its Volume Incentive Program Nearly a Year Early
Kalshi Is Ending Its Volume Incentive Program Nearly a Year Early
Bitcoin Price Holds the Low $80,000s as October’s “Uptober” Test Begins
Bitcoin Price Holds the Low $80,000s as October’s “Uptober” Test Begins
HSBC Names Hong Kong Dollar Stablecoin ‘RedCoin’ Ahead of 2026 Launch
HSBC Names Hong Kong Dollar Stablecoin ‘RedCoin’ Ahead of 2026 Launch
Cathie Wood's ARK Invest Buys NVIDIA, SpaceX & Tesla, Adds Kalshi to Its ETFs
Cathie Wood’s ARK Invest Buys NVIDIA, SpaceX & Tesla, Adds Kalshi to Its ETFs
Ripple and Brazil’s CSD BR Put Tokenized Fund Shares on XRP Ledger 
Ripple and Brazil’s CSD BR Put Tokenized Fund Shares on XRP Ledger 

Find Us on Socials

You may also like

Metaplanet Says Warrant Chapter Is Closed After $220M Value Wipeout

Metaplanet Says Warrant Chapter Is Closed After $220M Value Wipeout

Binance Pay Expands to PayPay Merchants Across Japan

Binance Pay Expands to PayPay Merchants Across Japan

Bitget USDT Withdrawals Due Sept 30 After Record $463M Outflow, Reserves at 131%

Bitget USDT Withdrawals Due Sept 30 After Record $463M Outflow, Reserves at 131%

Coinbase and VanEck 3D app icon blocks side-by-side on a reflective dark surface.

Coinbase Wallet Adds Polymarket to Its Crypto App Ecosystem

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information