SlowMist has traced malicious activity behind Bitget’s roughly $388 million security breach back to Aug. 31, more than three weeks before the exchange detected the unauthorized withdrawals, with investigators finding evidence that an attacker exploited a zero-day vulnerability in a third-party security product and later manipulated Bitget’s wallet withdrawal infrastructure.The findings provide the most detailed technical account yet of the Sept. 24 theft. In an investigation progress report, SlowMist described malicious activity involving two third-party security products, which it anonymized as “Product A” and “Product B,” as well as a wallet application host.
Bitget said Wednesday that separate investigations by SlowMist and Mandiant broadly match the attack path it previously disclosed. Both investigations found that compromised third-party security products ultimately enabled unauthorized access to the exchange’s wallet environment.
How Did the Attacker Get Inside Bitget’s Wallet Infrastructure?
SlowMist said the earliest malicious activity it has identified occurred on Aug. 31, when the attacker exploited a zero-day vulnerability affecting Product A. The attacker retrieved a database password from an environment variable and used a hidden script to access the product’s database.
Similar activity was subsequently detected on two additional nodes on Sept. 23 and Sept. 25, according to the report, whose timestamps use UTC+8.
The investigation also uncovered activity involving Product B. On Sept. 25, the attacker allegedly entered its management platform using the identity of an internal employee and attempted to inject system commands, change server configurations and upload malicious program files.
The findings add detail to Bitget’s earlier explanation that the attacker obtained high-level internal credentials and issued fraudulent withdrawal instructions without stealing private keys. FinanceFeeds previously reported that the breach compromised Bitget’s transaction-signing trust chain rather than its private keys.
Investor Takeaway
The forensic timeline shifts attention from private-key security toward the software and credentials surrounding the signing process. An exchange can keep its cryptographic keys intact while compromised infrastructure feeds apparently valid instructions into an authorized withdrawal system.
What Did the Custom Withdrawal Tool Actually Do?
SlowMist said investigators recovered a deleted and highly customized program designed specifically to interfere with the wallet system’s withdrawal process.
The tool could forge risk-control parameters, construct withdrawal requests and invoke the withdrawal process. The attacker also attempted to modify withdrawal records directly in the wallet database and initiate additional Bitcoin withdrawals.
Two fabricated BTC withdrawal orders entered processing but returned errors, according to SlowMist. The attacker then reviewed system logs, checked the status of the orders and made additional attempts.
Onchain verification placed the earliest confirmed attacker-controlled receipt at 2:31 a.m. UTC+8 on Sept. 25, when an address received 93 TRX. Eleven seconds later, another transfer delivered 0.84 ETH on Ethereum. SlowMist’s compiled transaction sequence subsequently stretched for roughly two hours and 52 minutes across multiple blockchains.
Bitget eventually calculated that approximately $387.5 million had been transferred to attacker-controlled addresses. The exchange has said cold wallets were unaffected and private-key compromise has been ruled out.
Investor Takeaway
The recovered tool suggests the attacker was not simply exploiting a single withdrawal endpoint. The ability to manipulate risk parameters and generate requests inside the wallet workflow points to a deeper operational-security problem in which trusted internal systems became part of the attack path.
Why Does the Aug. 31 Activity Matter?
The three-week gap between the earliest known compromise and the eventual asset drain is important because it suggests the attacker had time to study Bitget’s systems before executing the large withdrawals.
That period may help investigators determine how the attacker moved between Product A, Product B and the wallet environment, which SlowMist said remains under investigation. It may also clarify whether the earlier access was used for reconnaissance, credential collection or preparation of the custom withdrawal tooling.
FinanceFeeds previously reported that the attacker appeared to conduct small test transfers before the main $388 million drain, consistent with an operation that sought to understand whether fraudulent transactions could pass through Bitget’s controls.
How Much of the Stolen Crypto Can Still Be Recovered?
Bitget’s recovery effort remains active, but the stolen assets are continuing to move. NEAR Intents said its systems blocked attempts to route more than $50 million linked to the breach and froze another roughly $503,000 that had entered its infrastructure. Chainflip also said a broker rejected an attempted transaction involving attacker-linked funds.
Other assets have become harder to trace. On Wednesday, attacker-linked wallets moved about $3.9 million of stolen Zcash into the network’s shielded pool.
Bitget has meanwhile continued restoring operations. Its latest proof-of-reserves snapshot, taken Sept. 29, showed a total reserve ratio of 131%, while the company said Wednesday that it had replenished its Protection Fund to more than $300 million. Withdrawals are being restored in stages, with remaining tokens, fiat withdrawals and peer-to-peer services scheduled to return by Oct. 2.
Investor Takeaway
The operational recovery and the asset-recovery process are separate issues. Bitget can restore withdrawals and maintain reserve coverage even if much of the stolen crypto remains unrecovered; the longer-term financial impact will depend on how much can ultimately be frozen or returned.
