SECURITY ALERT · UPDATE 1 (follow-up to our 28 Sep alert)
Findings current as of SlowMist’s progress report dated 29 Sep and Mandiant’s status report dated 28 Sep, both published by Bitget at 05:20 UTC on 30 Sep.
The money left in under three hours. The foothold lasted 25 days.
SlowMist, one of two security firms Bitget hired after the 24 Sep theft, says the earliest malicious activity in the available logs dates to 31 Aug.
That day, according to SlowMist’s progress report, a service on a node of a third-party security product, which it calls “Product A”, was hit through a zero-day vulnerability.
The attacker ran a hidden script, read an environment variable holding a database password and connected to the database.
Similar hidden-script activity appeared on two more nodes on 23 and 25 Sep, SlowMist says.
Bitget puts the loss at about $387.5 million. It says private keys and cold wallets were not compromised.
If the keys were safe, what moved the money?
What does the SlowMist timeline show?
All times below are converted from the UTC+8 times in SlowMist’s report.
At 16:07 UTC on 24 Sep, the attacker entered the management platform of a second vendor tool, “Product B”, using an internal employee’s identity. It made three consecutive attempts to inject system commands.
It then submitted code through the platform’s web execution endpoint to write a relay file and assemble malicious programs in batches.
At 17:49 UTC, a malicious program began running on the host and executing theft.
At 18:31 UTC, the first verified on-chain transfer landed. SlowMist records 93 TRX, then 0.84 ETH eleven seconds later.
Chief executive Gracy Chen gave different amounts in a 28 Sep interview with The Block: 193 TRX and 0.184 ETH. Both accounts agree that the first transfers were small and sat below risk thresholds.
SlowMist’s compiled transfers run to 21:23 UTC, about 2 hours and 52 minutes in all.
Did anyone watch the quiet days between 31 Aug and 24 Sep?
How did the attacker get in?
Mandiant, part of Google Cloud, says in its status report that on 24 Sep a threat actor gained unauthorised privileged access to third-party security appliances “A” and “B”.
It deployed a web shell on appliance B and set up a command-and-control connection.
From there, Mandiant says, it moved laterally to Bitget’s production wallet job server and deployed malicious packages.
SlowMist recovered a “highly customized withdrawal tool” from files the attacker had deleted. SlowMist says the tool forged risk-control parameters, built withdrawal requests and called the withdrawal process.
That is a backend integrity failure, not a leaked cold-wallet seed phrase.
The two firms date the first access differently: Mandiant to 24 Sep, SlowMist to 31 Aug. Neither report says the investigation is finished.
When the vendor appliance is the door, who owns the lock?
Where did the funds go?
Bitget published the attacker’s main receiving addresses on EVM chains, the XRP Ledger, Zcash and Tron on 25 Sep. It offered 5% of any funds frozen or recovered through voluntary action.
The blockchain tracker MistTrack said on 30 Sep that stolen funds were being routed through CoW Protocol and Chainflip, Bitcoin.com News reported. MistTrack, SlowMist’s fund-tracking service, linked the scripts to suspected North Korean activity, according to the same report.
That is an unconfirmed allegation from a tracking service. The SlowMist and Mandiant reports that Bitget published do not name an attacker, and Bitget has not attributed the attack.
Bitget has not published a total for funds frozen or recovered.
Where does “the Protection Fund covers users” end and “the funds are still moving” begin?
What has Bitget done since?
Bitget restored bitcoin withdrawals on 28 Sep and ether on 29 Sep, and USDT is scheduled for 08:00 UTC today.
Chen told The Block the User Protection Fund, worth $465 million on 25 Sep, would absorb the loss and be topped back up to at least $300 million.
Related: [The withdrawal timetable -> bitget-restores-ether-withdrawals]] [link: the pre-drain test transfers
Protect yourself
- Ask whether your exchange publishes independent attestation of hot-wallet and warm-wallet controls, not only a proof-of-reserves ratio.
- Use withdrawal allow-lists and withdrawal delays where they are offered.
- Keep only working balances on any centralised venue.
- After an incident, check domains before connecting a wallet to any “recovery” site.
Related: How private keys work
What else was sitting on that appliance for 25 days?
Corrections and new evidence: [email protected]
This article was written by Dalia Haddadin, an AI author persona at CryptoWatchDesk, and was reviewed, fact-checked and edited by Akriti Seth. It is not investment advice. Dalia Haddadin holds no crypto assets.
