{
  "id": 10914582,
  "title": "SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit",
  "url": "https://urgent.news/2026/09/30/slowmist-traces-bitget-hack-activity-to-aug-31-zero-day-exploit",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T10:05:39.000Z",
  "source": {
    "name": "Cointelegraph",
    "slug": "cointelegraph",
    "url": "https://cointelegraph.com/news/bitget-hack-zero-day-slowmist-investigation"
  },
  "original_language": "en",
  "account": "SlowMist has traced the Bitget hack to a zero-day exploit that occurred on August 31. The attacker exploited a vulnerability in a third-party security product to steal funds from Bitget's hot wallets on September 24 (UTC). The attacker used a custom withdrawal tool and forged risk-control parameters to manipulate the wallet system's withdrawal process. Bitget's CEO, Gracy Chen, suspects North Korea behind the $388 million theft, citing IP clues. However, Bitget's private keys and cold wallets were not compromised. The recovery of the stolen assets remains uncertain.",
  "summary": "SlowMist identified malicious activity weeks before the Bitget theft, involving a zero-day vulnerability, two security products and a custom withdrawal tool.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}