- SlowMist said on September 29, 2026, that its investigation into the theft from Bitget’s hot wallets had identified malicious activity linked to two third-party security products.
- Bitget hired SlowMist on September 25 after the theft, and investigators found that the products’ environments had been compromised before the asset outflows began.
- The attacker exploited a zero-day vulnerability in one product and accessed the other product’s management platform using an employee account.
- SlowMist recovered a purpose-built tool that spoofed risk controls, generated withdrawal requests and triggered the wallet system’s withdrawal procedure.
SlowMist reported its findings as of September 29, four days after Bitget brought in the security company to investigate the theft. The two affected third-party security products were identified only as Product A and Product B.
Product A compromised through zero-day vulnerability
SlowMist determined that the earliest detected malicious activity occurred on August 31 on one of Product A’s nodes. The attacker compromised the service through a zero-day vulnerability, launched a stealth script within the service process and executed a command to read an environment variable containing the database password before connecting to the database.
Researchers recorded similar activity involving stealth scripts on two additional Product A nodes on September 23 and September 25. According to the report, those service environments had been compromised before the asset outflows began.
On the morning of September 25, the attacker also accessed Product B’s management platform using an internal employee account. The attacker made three attempts to inject system commands into Product B task parameters to write malicious files.
Using the command-execution endpoint in the platform’s web interface, the attacker then tried to change the server configuration, write a file to relay communications, and download and compile batches of malicious program files.
Recovered tool targeted wallet withdrawals
SlowMist recovered files that the attacker had deleted, including a purpose-built asset-draining tool tailored to the wallet system’s logic. The tool spoofed risk-control parameters, generated withdrawal requests and triggered the corresponding procedure.
Host logs showed that the malware began operating and stealing crypto assets during the night of September 25. In the first blockchain transfer confirmed by SlowMist, the attacker’s address received 93 TRX. Eleven seconds later, an address on the Ethereum network received 0.84 ETH.
Confirmed transfers continued for about two hours and 52 minutes across multiple blockchains.
After the transfers began, the attacker also tried to modify withdrawal records directly in the wallet database and run withdrawal jobs locally on the host. Logs showed that two fabricated bitcoin withdrawal orders entered processing, but both ended in errors.
The attacker subsequently reviewed logs, checked order statuses and made additional withdrawal attempts.
Investigation remains ongoing
SlowMist’s report did not specify the total value of the stolen assets, provide a full list of affected tokens, identify Product A or Product B, or name the attacker or group behind the incident. The company also did not establish the definitive initial compromise vector for the broader system.
At the time the report was prepared, SlowMist said it was still investigating how the attacker moved between the systems involved.
Source: Incrypted
