Thu. Oct 1st, 2026

SlowMist Traces Bitget Attackers Back 25 Days Before $388M Theft

ByJohan Shamshad

September 30, 2026 #Bitget
HackHack

Attackers linked to Bitget’s $387.5 million security breach were operating inside compromised infrastructure nearly four weeks before the money started leaving the exchange, according to new forensic findings from blockchain security firm SlowMist.

The September 24 theft was already known to involve Bitget’s backend wallet infrastructure rather than stolen private keys. But a SlowMist investigation progress report released on September 30 pushes the earliest known malicious activity back to August 31, materially changing the timeline of the incident.

The Earliest Known Compromise Dates Back to August 31

SlowMist said investigators found malicious activity on a node belonging to an unnamed third-party security product, referred to in the report as “Product A.” The attacker exploited a zero-day vulnerability in the product and ran a hidden script under the affected service process.

The script attempted to read sensitive information from the environment, including a database password stored in an environment variable, before connecting to the database. Similar hidden-script activity later appeared on two other nodes on September 23 and September 25.

Those records indicate that the relevant service environment had already been compromised before the large-scale asset transfers began. They do not necessarily prove that the attacker remained continuously active inside the system during every day between August 31 and September 24, but they establish an intrusion point roughly 25 days before the theft.

The finding adds technical detail to Bitget’s earlier disclosure that a vulnerability in a third-party security product allowed an attacker to obtain privileged internal access. Dave Finances previously reported how Bitget said its backend wallet system was compromised even though the cryptographic keys controlling the affected wallets were not extracted.

A Second Security Product Led Into the Withdrawal System

The attack later moved into another component that SlowMist calls “Product B.” According to the forensic timeline, the attacker used an internal employee identity to enter the second product’s management platform.

At about 16:07 UTC on September 24, the attacker began attempting to inject system commands through task parameters. SlowMist also found attempts to change server configurations, create relay files and assemble malicious programs through a web-based execution interface.

The most important discovery came from files the attacker had deleted. Investigators recovered a highly customized withdrawal tool apparently designed specifically around Bitget’s wallet withdrawal logic.

The program could forge risk-control parameters, construct withdrawal requests and call the withdrawal process itself. Host logs indicate the tool began executing at approximately 17:49 UTC.

That distinction matters because the attacker was not simply stealing credentials and manually submitting ordinary customer withdrawals. The recovered tooling appears to have been built to manipulate the infrastructure that decides whether a withdrawal should be processed.

The On-Chain Theft Ran for About 2 Hours and 52 Minutes

The first verified on-chain transfer occurred at 18:31 UTC on September 24, when an attacker-controlled address received 93 TRX. Eleven seconds later, another address received 0.84 ETH.

Transfers then accelerated across several blockchain networks. SlowMist’s compiled timeline places the final transfer at approximately 21:23 UTC, giving the confirmed on-chain theft window a duration of about two hours and 52 minutes.

After funds began leaving, investigators also found evidence that the attacker attempted to alter withdrawal records in the wallet database and initiate additional Bitcoin withdrawals. Two forged BTC withdrawal orders reportedly generated errors, after which the attacker checked logs and transaction status and continued attempting to manipulate the process.

Bitget ultimately revised the value of affected assets from an initial $351.6 million to approximately $387.5 million after additional Zcash and TRON transactions were included. The exchange says its cold wallets were unaffected and that investigators have ruled out a private-key compromise.

Bitget has been restoring services in phases since the breach, with Bitcoin withdrawals reopening first and Ethereum following. Dave Finances has been tracking the exchange’s withdrawal recovery, while Bitget’s published schedule called for USDT withdrawals across Ethereum, BNB Smart Chain, Solana and Tron to resume on September 30.

This Was a Failure Before the Private Key

The most important lesson from the SlowMist findings is that protecting private keys is not enough to protect a centralized exchange.

Private keys are often treated as the final security boundary in crypto custody. If the keys remain inside hardened signing systems or cold storage, the assumption is that the assets are safe.

Bitget shows why that assumption can fail.

A signing system still depends on other infrastructure to tell it what transaction should be signed. If an attacker can compromise the systems that create withdrawal instructions, manipulate risk-control parameters and present a fraudulent transaction as legitimate, the cryptographic signing layer can operate exactly as designed while still authorizing a theft.

That shifts the security discussion away from simply asking whether keys were stolen. Investors also need to think about the systems sitting before those keys: transaction-generation servers, employee identities, security appliances, approval workflows, database permissions and third-party integrations.

The Unnamed Vendors May Be the Bigger Industry Question

SlowMist’s use of “Product A” and “Product B” leaves one of the biggest questions unresolved.

If those products are widely deployed across crypto exchanges or other financial infrastructure, the Bitget incident could represent more than an isolated exchange breach. Other organizations using the same software may need to determine whether they were exposed to the same zero-day, whether similar hidden scripts appeared in their environments and whether compromised credentials were created before the vulnerability was patched.

If the products were specific to Bitget’s architecture, the broader risk would be more contained. Right now, the public does not have enough information to know which scenario applies.

There are legitimate reasons investigators may avoid immediately naming vulnerable vendors, particularly while remediation and forensic work remain underway. But from an investor and industry-risk perspective, those identities will eventually matter because third-party security software is supposed to reduce an institution’s attack surface, not become the route into its highest-value systems.

Recovery Does Not End When Withdrawals Restart

Bitget’s immediate operational problem is increasingly giving way to a longer recovery problem.

The exchange says its User Protection Fund, valued above $464 million when the incident was disclosed, is sufficient to cover the financial impact and that customer account balances remain unaffected. But restoring withdrawal access does not recover the stolen cryptocurrency.

The attacker has continued moving portions of the assets through different networks and conversion routes. More than $80 million in stolen XRP moved from its original holding wallets during the first days after the incident, a development Dave Finances examined as recovery options narrowed.

Investigators have also watched funds pass through cross-chain infrastructure as the attacker attempts to move assets into forms that are harder to freeze. In one recent example, a broker handling a Chainflip transaction rejected a deposit linked to the Bitget attacker, sending the assets back instead of completing the intended route.

The financial loss therefore remains only one part of the story. Bitget must show that the compromised third-party pathway has been fully eliminated, that internal identities and withdrawal infrastructure have been hardened, and that the rebuilt system can operate under normal customer load without introducing another weak point.

For investors, the September 30 SlowMist report makes the breach more significant than a single night of unauthorized withdrawals. The first visible money movement lasted less than three hours. The underlying compromise began weeks earlier.

That gap is where the real security failure occurred — and until investigators explain exactly how the attacker moved from the two unnamed security products into Bitget’s production withdrawal environment, it remains the most important unanswered part of the $387.5 million theft.

“`

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *