Blockchain security firm Slowmist reported that attackers accessed Bitget’s infrastructure on August 31, nearly four weeks prior to the theft of approximately $388 million. The breach originated from a zero-day vulnerability in a third-party security product, allowing intruders to extract database credentials and run hidden scripts. Although private keys were not stolen, the attackers manipulated internal approval systems to authorize legitimate-looking transfers. Arkham Intelligence data indicates $228 million was moved across seven chains within 18 minutes, with XRP accounting for roughly $153 million of the total loss.
Following the exfiltration, suspects linked to North Korea utilized CoW Protocol and Chainflip to launder funds by swapping assets into bitcoin. While some laundering attempts were blocked or reversed by protocols like Near Intents and Chainflip brokers, Slowmist founder Cos noted that anti-money laundering checks often lag behind sophisticated hacking techniques. Bitget stated its User Protection Fund, holding over $464 million, covers the losses, and withdrawal services are being restored in stages starting with bitcoin.
The revelation that attackers maintained persistent access for 25 days highlights critical gaps in real-time intrusion detection and log monitoring within centralized exchange infrastructure. Relying on third-party security products without rigorous independent verification creates single points of failure, particularly when zero-day vulnerabilities bypass traditional defenses. This incident underscores the necessity for exchanges to implement stricter segmentation between external vendor tools and core wallet management systems to prevent credential harvesting.
From an institutional adoption perspective, the speed of asset movement—$228 million in 18 minutes—demonstrates the fragility of manual or semi-automated approval workflows against automated attack scripts. The subsequent laundering efforts reveal an arms race between crypto-native compliance mechanisms and state-sponsored actors using decentralized finance primitives. Exchanges must now prioritize behavioral analytics that detect anomalous internal system usage patterns, rather than relying solely on perimeter defense, to mitigate operational risks associated with prolonged unauthorized access.


