
⏱ 2 min read
▲ 0.12%
▲ 0.54%
Investigators say attackers exploited a third‑party security product weeks before the Sept. 24 hot‑wallet drain and used a tailored tool to forge withdrawal risk checks.
Security firm SlowMist linked Bitget’s $388 million hot‑wallet theft to a zero‑day vulnerability first exploited on Aug. 31, weeks before the Sept. 24 (UTC) drain. The firm said the attacker moved funds to their own addresses across several blockchains after breaching systems tied to two third‑party security products and a wallet application host.
According to a SlowMist progress report, the attacker planted a hidden script that accessed the database of an unnamed third‑party security product (“Product A”) after retrieving its password from an environment variable. Similar activity appeared on two other nodes on Sept. 23 and Sept. 25 (UTC+8), the firm said.
On Sept. 25, the attacker also accessed the management platform of a second security product (“Product B”) using an internal employee’s identity, SlowMist said. From there, they attempted to inject system commands, alter server configurations and upload malicious program files. The firm added that it is still examining how the attacker moved between the affected systems.
SlowMist said it recovered a deleted, highly customized tool used to manipulate the wallet system’s withdrawal process. The tool forged risk‑control parameters, constructed withdrawal requests and invoked the withdrawal workflow — indicating the attacker had reached into the exchange’s operational controls rather than merely sending raw transactions.
The on‑chain timeline corroborates the operational breach window. SlowMist’s verification shows the earliest transfer at 2:31 am (UTC+8) on Sept. 25, when an attacker‑controlled address received 93 TRX, followed 11 seconds later by 0.84 ETH on Ethereum. Compiled transfers spanned about two hours and 52 minutes across multiple blockchains, ending at 5:23 am (UTC+8) that day.
The attacker also tried to modify withdrawal records directly in the wallet database and trigger additional Bitcoin withdrawals, SlowMist reported. Two fabricated BTC withdrawal orders entered processing but returned errors; logs show the attacker reviewed statuses and made further attempts.
The combination of a third‑party zero‑day, use of an internal employee identity and a bespoke withdrawal tool suggests an operator‑level compromise that touched security tooling and workflow. In practice, hot wallets are connected to systems that enforce risk checks; if those checks are forged or bypassed, automated processes can move funds across chains quickly before manual intervention can catch up.
Key uncertainties remain. SlowMist has not named the affected vendors or detailed how the attacker obtained or spoofed the internal identity, and the firm said its investigation into lateral movement between systems is ongoing.
This content is for informational purposes only and does not constitute financial advice.
🧠 HafidWatch Take
The unresolved details about how the attacker obtained or spoofed the internal employee identity leave a critical gap in fully understanding the breach’s scope and mechanics. Until investigations clarify these lateral movement paths, it’s difficult to assess the effectiveness of vendor patches and identity controls alone in preventing similar attacks. Greater transparency on the zero-day fix and internal access methods will be essential to evaluate risk reduction and tailor defenses.
Daily crypto intelligence. Before the market opens.
Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.
✓ Free forever · ✓ No spam · ✓ 50+ sources monitored



