SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit
SlowMist identified malicious activity weeks before the Bitget theft, involving a zero-day vulnerability, two security products and a custom withdrawal tool.
SlowMist has traced the Bitget hack to a zero-day exploit that occurred on August 31. The attacker exploited a vulnerability in a third-party security product to steal funds from Bitget's hot wallets on September 24 (UTC). The attacker used a custom withdrawal tool and forged risk-control parameters to manipulate the wallet system's withdrawal process.
Bitget's CEO, Gracy Chen, suspects North Korea behind the $388 million theft, citing IP clues. However, Bitget's private keys and cold wallets were not compromised. The recovery of the stolen assets remains uncertain.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.