Bitget Security Breach Linked to August 31 Zero-Day Attack, SlowMist Investigation Reveals
Security firm SlowMist has traced malicious operations back to several weeks prior to the Bitget hack, uncovering a zero-day security flaw, compromised security tools and specialized withdrawal software.

Security firm SlowMist has determined that the first recorded malicious operations connected to the $388 million Bitget security breach occurred on Aug. 31, when a bad actor took advantage of a zero-day security flaw that impacted a third-party security solution.
The theft from Bitget's hot wallets took place on Sept. 24 (UTC), with the perpetrators moving digital assets to wallets under their control spanning multiple blockchain networks. The investigation conducted by SlowMist uncovered malicious operations that targeted two separate third-party security solutions and a wallet application hosting platform.
Based on a progress update released by SlowMist, the perpetrator deployed a concealed script to gain access to the database of what the firm referred to as "Product A," following the extraction of its password from an environment variable. Comparable malicious operations were subsequently discovered on two additional nodes on Sept. 23 and Sept. 25. The timeline and timestamps referenced in the analysis utilize UTC+8 formatting.
On Sept. 25, the perpetrator additionally gained unauthorized access to the administrative interface of a secondary security solution, designated by SlowMist as "Product B," utilizing the credentials of an internal staff member. According to SlowMist, the attacker proceeded to attempt injecting system-level commands, modifying server settings and uploading files containing malicious code.
The security firm stated that its forensic analysis continues and that investigators are still working to determine the methods the perpetrator used to navigate between the compromised infrastructure components.
Attacker used custom withdrawal tool
The cybersecurity firm reported that it successfully retrieved a previously deleted, extensively customized program that was engineered to manipulate the withdrawal functionality of the wallet infrastructure. The program created falsified risk-control parameters, assembled withdrawal transaction requests and triggered the withdrawal execution process.
Through onchain analysis conducted by SlowMist, investigators identified the earliest confirmed transfer occurring at 2:31 am UTC+8 on Sept. 25, during which an address under the attacker's control received 93 TRX, succeeded 11 seconds afterward by 0.84 Ether on the Ethereum network. The comprehensive transfer documentation assembled by investigators covered approximately two hours and 52 minutes spanning numerous blockchain platforms, continuing until 5:23 am on that same date.
The perpetrator additionally attempted to alter withdrawal transaction records directly within the wallet database infrastructure and initiate supplementary Bitcoin withdrawal transactions. According to SlowMist, two counterfeit BTC withdrawal requests entered the processing pipeline but generated error responses, following which the perpetrator examined system logs, verified order status information and conducted additional attempts.
In an update released on Sept. 25, Bitget disclosed that approximately $387.5 million had been transferred to addresses controlled by the attackers distributed across multiple networks.
In subsequent communications with Cointelegraph, Bitget CEO Gracy Chen explained that the security compromise originated from a security weakness in a third-party security solution that enabled the perpetrator to acquire "high-level internal credentials" and execute unauthorized withdrawal instructions. Chen emphasized that Bitget's private cryptographic keys and cold storage wallets remained uncompromised throughout the incident.
Recovery efforts for the stolen digital assets are ongoing at Bitget. During an appearance on Cointelegraph's Chain Reaction program, Chen stated she remained "not very optimistic" regarding the prospects of completely recovering the approximately $388 million in stolen funds, citing the minimal recovery achieved following Bybit's 2025 security breach as a comparative example.