Attackers behind the $387.5 million Bitget hack had a foothold inside parts of the exchange’s infrastructure almost four weeks before any funds moved, according to interim forensic findings released on September 30 by blockchain security firm SlowMist and cybersecurity firm Mandiant.
Both firms said the attacker did not steal private keys. Instead, the intruder compromised third-party security products, in one case through a zero-day vulnerability, moved into Bitget’s wallet environment and used a custom withdrawal tool to send transfers that the exchange’s own systems accepted as valid.
A zero-day vulnerability is a software flaw that is unknown to the vendor and has no available fix at the time it is exploited. Neither SlowMist nor Mandiant named the affected vendors, and Bitget has not named them either. Both firms described their findings as interim.
Bitget, a Seychelles-based centralized cryptocurrency exchange, hired the two firms in the hours after its September 24 breach. The attack hit some of the exchange’s hot wallets, which stay connected to the internet to process routine withdrawals, and warm wallets, which sit between hot wallets and offline storage. Bitget’s cold wallets and its separately operated self-custody product, Bitget Wallet, were not affected, the exchange has said.
What SlowMist Found
SlowMist said Bitget commissioned it to investigate the hot wallet theft. Its English-language summary, current as of September 29 and posted on September 30, uses China Standard Time (UTC+8), eight hours ahead of Coordinated Universal Time (UTC). The firm listed five findings:
- Malicious activity on a third-party product that exploited a zero-day vulnerability.
- Unauthorized access on September 25 (UTC+8) to a third-party product’s management platform using an internal employee identity.
- Recovery of a highly customized withdrawal tool built around the wallet system’s withdrawal logic.
- On-chain transfers starting at 02:31 on September 25 (UTC+8) and running across multiple blockchains for about 2 hours and 52 minutes.
- Later attempts to alter withdrawal records and trigger additional Bitcoin (BTC) withdrawals.
SlowMist said it is still establishing how the attacker moved between those systems.
A Timeline That Starts on August 31
A longer Chinese-language account from SlowMist co-founder Yu Xian, known online as Cos, adds detail that the English summary did not include. All times below are converted from UTC+8 to UTC.
The earliest malicious activity dates to August 31. On a node of a system Cos refers to only as “Product A,” the zero-day allowed the attacker to run a hidden script under the service process, attempt to read database passwords and environment variables, and connect to the database. Similar hidden-script activity appeared on two other nodes on September 23 and September 25 (UTC+8). SlowMist reads this as evidence that the environment was already compromised before funds left.
The attacker then entered a second system, “Product B,” using an internal employee identity. From about 16:07 UTC on September 24, task parameters were used to splice in system commands and attempt to write malicious files. Code submitted through a web execution interface then tried to change server configuration, place relay files and assemble malware in pieces. SlowMist recovered, from deleted files, a custom tool that forged withdrawal parameters and called Bitget’s withdrawal process. Malicious programs on the host started at about 17:49 UTC.
The first verified on-chain outflow came at 18:31 UTC: 93 TRX, the native token of the TRON blockchain, sent to an attacker address, followed 11 seconds later by 0.84 Ether (ETH). Transfers continued until 21:23 UTC. After funds began leaving, logs show attempts to edit withdrawal records in the wallet database and two forged BTC withdrawal orders that failed after 21:22 UTC.
The 18:31 UTC start matches the minute Bitget first said its systems detected unauthorized transfers on September 24.
What Mandiant Found
Mandiant, Google Cloud’s incident response and threat intelligence unit, released a parallel note through Bitget. It said the attacker gained unauthorized access to certain third-party security appliances, moved laterally into Bitget Exchange’s wallet environment, and obtained access to warm and hot wallets. Lateral movement refers to an intruder shifting from one compromised system to others inside the same network.
According to Cos’s summary of both reports, Mandiant found no evidence that Bitget’s private keys were leaked and confirmed that cold wallets were not affected. After establishing persistent access through the third-party devices, the attacker moved to production wallet task servers and deployed malware. Both firms said they are still mapping the exact path between systems.
Bitget’s Response
Bitget thanked SlowMist and said the firm had confirmed malicious activity on third-party security products, including a zero-day, and recovered the tool used for the unauthorized withdrawals. The exchange said the findings align with the attack path it previously shared and that it is now focusing on applying them and tightening controls. Bitget’s Chinese-language account posted the same message.
The forensic notes support what Bitget told users on September 28, when it reopened BTC withdrawals and said the attacker obtained high-level internal credentials through a vulnerability in a third-party security product. Until today, that account came only from Bitget itself.
How the Findings Fit the Record So Far
Bitget first put the loss at $351.6 million, then raised it to about $387.5 million on September 25 after adding Zcash (ZEC) and TRON transfers from the same attack window. It said the revision did not reflect a second breach and launched a 5% recovery bounty for frozen funds.
Blockchain security firm GoPlus Security had already concluded that the attacker made Bitget’s own signing system approve the transfers, with the largest wave of about $185 million moving in roughly one minute at 19:16 UTC on September 24. SlowMist’s recovered withdrawal tool offers the first independent evidence of how those forged instructions reached the signing process.
Bitget has kept to its phased withdrawal schedule, with Tether (USDT) due on September 30 and remaining tokens, fiat and peer-to-peer (P2P) services on October 2. The exchange says its User Protection Fund, which held more than $464 million at the time of the incident, covers the loss.
Laundering Continues
SlowMist’s on-chain tracking unit, MistTrack, has continued to follow the stolen funds. Cos said suspected operators are placing automated orders on CoW Protocol, a decentralized exchange aggregator, with recipient addresses pre-set to deposit contracts on Chainflip, a cross-chain swap network, before bridging into Bitcoin.
He said Chainflip has tried to block some flows, but automated splitting across bridges is outpacing Anti-Money Laundering (AML) and Know Your Transaction (KYT) checks. Once funds reach Bitcoin, he said, CoinJoin, a technique that mixes multiple users’ transactions to obscure their origin, is being used.
Earlier, cross-chain protocol THORChain declined a request from Bitget Chief Executive Officer (CEO) Gracy Chen to refuse known attacker addresses, citing its permissionless design. On-chain investigator ZachXBT has also identified five people he says are laundering the funds for suspected North Korean operators.
Attribution to North Korea remains a working theory from Bitget, blockchain analytics firm Elliptic, and on-chain investigators. No government has issued a formal attribution.
What Remains Unanswered
Several questions remain open. The firms have not identified who developed the zero-day, which products “Product A” and “Product B” are, or how the internal employee identity was obtained or forged. It is also unclear how long persistent access lasted between August 31 and September 24, and how much of the stolen funds has been frozen compared with the amount already swapped into Bitcoin.
Bitget has said it expects to publish a fuller security report this week. SlowMist and Mandiant have both described their September 30 findings as interim.
Also Read: Metaplanet Says Warrant Chapter Is Closed After $220M Value Wipeout
