Blockchain security firm SlowMist has traced the earliest confirmed malicious activity behind Bitget’s 388 million USD theft to August 31 — nearly a month before funds left the exchange’s hot wallets — and the forensic trail runs through two third-party security products, a stolen employee identity, and a custom-built withdrawal tool that forged risk-control parameters.
- Blockchain security firm SlowMist has traced the earliest confirmed malicious activity behind Bitget’s 388 million USD theft to August 31 — nearly a month before funds left the exchange’s hot wallets — and the forensic trail runs through two third-party security products, a stolen employee identity, and a custom-built withdrawal tool that forged risk-control parameters.
- Product A: the zero-day foothold
- Product B: a stolen identity
- The custom withdrawal tool
- Recovery outlook dims
The findings, published in a SlowMist investigation progress report, reconstruct how attackers compromised Bitget’s infrastructure long before the September 24 (UTC) theft made headlines. Attackers transferred assets from Bitget hot wallets to addresses they controlled across several blockchains, but the new report shows the intrusion was already deep inside the exchange’s vendor stack weeks earlier.
Product A: the zero-day foothold
On August 31, an attacker exploited a zero-day vulnerability in a third-party security product — anonymized by SlowMist as “Product A” — using a hidden script to access the product’s database after retrieving its password from an environment variable. Storing database credentials in environment variables is a common but widely criticized practice, and the attack path suggests the zero-day allowed the intruder to reach far enough into the host to read them.
Similar activity was later detected on two other nodes on September 23 and September 25, indicating the attacker maintained and expanded access across Bitget’s infrastructure rather than striking once and retreating. The timestamps in the SlowMist report are given in UTC+8.
Product B: a stolen identity
On September 25 — the day after the main theft — the attacker accessed the management platform of a second security product, “Product B,” using an internal employee’s identity. From that position, SlowMist said the intruder attempted to inject system commands, alter server configurations and upload malicious program files. SlowMist emphasized that its investigation remains ongoing, and it is still working to determine exactly how the attacker pivoted between the affected systems.
The picture that emerges is of a patient, multi-stage supply-chain compromise: breach one vendor with a zero-day, harvest credentials, wait, then use a second vendor’s management plane — entered via an employee account — to entrench further. Bitget CEO Gracy Chen has previously said the breach stemmed from a vulnerability in a third-party security product that gave the attacker high-level internal credentials, while insisting Bitget’s own private keys and cold wallets were never compromised.
The custom withdrawal tool
Perhaps the most revealing artifact recovered by SlowMist is a deleted, highly customized tool built specifically to manipulate the wallet system’s withdrawal process. The tool forged risk-control parameters, constructed withdrawal requests and invoked the withdrawal process directly — effectively impersonating legitimate withdrawal traffic well enough to slip past the controls designed to stop exactly this scenario.
On-chain verification by SlowMist found the earliest confirmed transfer at 2:31 am UTC+8 on September 25, when an attacker-controlled address received 93 TRX, followed 11 seconds later by 0.84 Ether on Ethereum — small test transactions that are a hallmark of infrastructure validation before a large-scale sweep. The compiled transfer records span roughly two hours and 52 minutes across multiple blockchains, extending to 5:23 am that day.
The attacker also attempted to modify withdrawal records directly in the wallet database and trigger additional Bitcoin withdrawals. Two fabricated BTC withdrawal orders entered processing but returned errors — after which, in a detail that reads like a debugging session, the attacker reviewed logs, checked order status and made further attempts.
Recovery outlook dims
Bitget has said approximately 387.5 million USD was transferred to attacker-controlled addresses across several networks. Recovery prospects are bleak: speaking on Cointelegraph’s Chain Reaction podcast, Chen said she was “not very optimistic” about fully recovering the roughly 388 million USD lost, pointing to the limited recovery achieved after Bybit’s 2025 hack as the realistic reference point. Chen has also said she suspects North Korean actors may be behind the attack, citing IP clues.
For the broader industry, the SlowMist report’s lesson is uncomfortable: the weakest link was not a private key or a smart contract, but the security vendors themselves. When the products meant to protect an exchange become the entry vector, every operator relying on third-party tooling is suddenly re-examining its own vendor stack — and its own environment variables.
Price snapshot at publication (CoinGecko): BTC 84,524 USD — ETH 2,702.58 USD — SOL 120.97 USD.
db password sitting in an environment variable at a top exchange, in 2026. devs never learn
env var creds are dev convenience 101, bitget has zero excuse at 388M scale
db password sitting in an environment variable and a zero-day in a third party security product. the irony of buying security software that opens the door
This is why enterprise security tooling means nothing if the vendor stack is the attack surface. SlowMist tracing it back a full month before the 388m even moved is the scary part
aug 31 is the wildest part. they were inside almost a full month before funds moved and nothing flagged a forged risk-control param
a custom built tool to forge withdrawal limits is organized crime energy, not some solo drainer with a browser wallet
weeks of dwell time across multiple nodes and nobody flagged it until funds left the hot wallets. internal detection at exchanges is basically decorative
Using a stolen employee identity to reach a second security product the day after the theft says they planned to stay in longer. Expect more exchanges to quietly rotate vendor credentials now