Blockchain security firm SlowMist has traced the earliest malicious activity associated with Bitget’s $388 million theft back to August 31, when an attacker exploited a zero-day vulnerability in a third-party security product. The actual fund extraction occurred on September 24, when assets were moved from Bitget’s hot wallets to addresses controlled by the attackers across multiple blockchains. SlowMist’s investigation revealed that the breach involved two distinct third-party security products and a wallet application host. On September 25, the attacker accessed the management platform of a second security product using an internal employee’s identity, attempting to inject system commands and alter server configurations.

The stolen funds, totaling approximately $387.5 million according to Bitget’s September 25 update, were transferred over a period spanning about two hours and 52 minutes. SlowMist recovered a customized tool used to manipulate the wallet system’s withdrawal process, which forged risk-control parameters and constructed fraudulent withdrawal requests. Bitget CEO Gracy Chen confirmed that the breach stemmed from a vulnerability allowing the acquisition of high-level internal credentials, though private keys and cold wallets remained secure. Chen expressed limited optimism regarding full asset recovery, citing precedents such as the Bybit hack.