Blockchain security firm SlowMist has traced the earliest malicious activity associated with Bitget’s $388 million theft back to August 31, when an attacker exploited a zero-day vulnerability in a third-party security product. The actual fund extraction occurred on September 24, when assets were moved from Bitget’s hot wallets to addresses controlled by the attackers across multiple blockchains. SlowMist’s investigation revealed that the breach involved two distinct third-party security products and a wallet application host. On September 25, the attacker accessed the management platform of a second security product using an internal employee’s identity, attempting to inject system commands and alter server configurations.
The stolen funds, totaling approximately $387.5 million according to Bitget’s September 25 update, were transferred over a period spanning about two hours and 52 minutes. SlowMist recovered a customized tool used to manipulate the wallet system’s withdrawal process, which forged risk-control parameters and constructed fraudulent withdrawal requests. Bitget CEO Gracy Chen confirmed that the breach stemmed from a vulnerability allowing the acquisition of high-level internal credentials, though private keys and cold wallets remained secure. Chen expressed limited optimism regarding full asset recovery, citing precedents such as the Bybit hack.
This timeline reconstruction highlights a critical failure in supply chain security within cryptocurrency infrastructure. By identifying an August 31 zero-day exploit as the starting point, SlowMist demonstrates that sophisticated attacks often involve prolonged reconnaissance and lateral movement long before the final exfiltration event. The compromise of third-party security products specifically undermines the trust model upon which many exchanges rely, suggesting that external audits and vendor vetting processes may be insufficient against novel vulnerabilities in widely deployed tools.
The operational implications extend beyond immediate financial loss to broader market structure concerns. The use of internal employee identities to access management platforms indicates potential weaknesses in access control protocols and insider threat mitigation. As exchanges continue to integrate complex third-party solutions for custody and compliance, the attack surface expands significantly. This incident serves as a stark reminder that hot wallet security is only as robust as its weakest linked component, necessitating more rigorous isolation of critical withdrawal functions from general administrative interfaces.


