SlowMist Details Attack on Bitget’s Hot Wallets

4 Min Read Tags:
  • SlowMist said on September 29, 2026, that its investigation into the theft from Bitget’s hot wallets had identified malicious activity linked to two third-party security products.
  • Bitget hired SlowMist on September 25 after the theft, and investigators found that the products’ environments had been compromised before the asset outflows began.
  • The attacker exploited a zero-day vulnerability in one product and accessed the other product’s management platform using an employee account.
  • SlowMist recovered a purpose-built tool that spoofed risk controls, generated withdrawal requests and triggered the wallet system’s withdrawal procedure.

SlowMist reported its findings as of September 29, four days after Bitget brought in the security company to investigate the theft. The two affected third-party security products were identified only as Product A and Product B.

Product A compromised through zero-day vulnerability

SlowMist determined that the earliest detected malicious activity occurred on August 31 on one of Product A’s nodes. The attacker compromised the service through a zero-day vulnerability, launched a stealth script within the service process and executed a command to read an environment variable containing the database password before connecting to the database.

Researchers recorded similar activity involving stealth scripts on two additional Product A nodes on September 23 and September 25. According to the report, those service environments had been compromised before the asset outflows began.

On the morning of September 25, the attacker also accessed Product B’s management platform using an internal employee account. The attacker made three attempts to inject system commands into Product B task parameters to write malicious files.

Using the command-execution endpoint in the platform’s web interface, the attacker then tried to change the server configuration, write a file to relay communications, and download and compile batches of malicious program files.

Recovered tool targeted wallet withdrawals

SlowMist recovered files that the attacker had deleted, including a purpose-built asset-draining tool tailored to the wallet system’s logic. The tool spoofed risk-control parameters, generated withdrawal requests and triggered the corresponding procedure.

Host logs showed that the malware began operating and stealing crypto assets during the night of September 25. In the first blockchain transfer confirmed by SlowMist, the attacker’s address received 93 TRX. Eleven seconds later, an address on the Ethereum network received 0.84 ETH.

Confirmed transfers continued for about two hours and 52 minutes across multiple blockchains.

After the transfers began, the attacker also tried to modify withdrawal records directly in the wallet database and run withdrawal jobs locally on the host. Logs showed that two fabricated bitcoin withdrawal orders entered processing, but both ended in errors.

The attacker subsequently reviewed logs, checked order statuses and made additional withdrawal attempts.

Investigation remains ongoing

SlowMist’s report did not specify the total value of the stolen assets, provide a full list of affected tokens, identify Product A or Product B, or name the attacker or group behind the incident. The company also did not establish the definitive initial compromise vector for the broader system.

At the time the report was prepared, SlowMist said it was still investigating how the attacker moved between the systems involved.

Source: Incrypted

TAGGED:
Trump, Tech Giants Agree on Four Oversight Levels for ‘Super Intelligence’ Era

U.S. President Donald Trump signed an order directing federal agencies to use “super intelligence” terminology; he and representatives of six companies also signed a voluntary four-level oversight accord.

5 Min Read
1inch Releases Digital Publication ReDeFine Money, Will Donate Proceeds to Charity

1inch released a digital edition of reDeFine Money on Written.app after its limited June 2026 print debut and said all digital-sale profits will go to a selected education-focused charity.

4 Min Read
OpenAI Introduces Dots, AI Agents That Work While You Sleep

OpenAI introduced ChatGPT Space, a shared workspace for project knowledge from people and AI agents, available on Pro, Business and Enterprise plans via ChatGPT’s desktop and web apps.

3 Min Read
Trump Considers Former SEC Chair Jay Clayton for AI Adviser Role

Axios reported that Trump is considering Director of National Intelligence Jay Clayton as White House AI adviser and expects to decide within three to four days, with no final choice…

3 Min Read
Higgsfield Details AI Video Generation Costs at $5.4 Billion Valuation

Higgsfield launched Cinema Studio 4.0, Genjutsu, Supercomputer and 3D Jutsu in August and September 2026, adding AI filmmaking, video reworking, task automation and 3D scene editing to its shared-credit platform.

4 Min Read