SlowMist Discloses Bitget Investigation update on hot wallet theft; attack involved a vulnerability in a third-party security product
BIBIBI
AT A GLANCE
SlowMist said that the Bitget hot wallet theft incident involved a zero-day vulnerability in a third-party product, unauthorized access, and a customized withdrawal tool, and that the investigation is ongoing.
Article
SlowMist Discloses Bitget Investigation update on hot wallet theft; attack involved a vulnerability in a third-party security product
BlockBeats reports that September 30, SlowMist published a statement saying that Bitget has commissioned the SlowMist security team to investigate the hot wallet asset theft incident September 25.
As of September 29, the SlowMist investigation found that the attack involved a third-party security product, malicious activity on wallet application hosts, and a withdrawal tool custom-developed by the attacker.
The investigation showed that the attacker primarily carried out the attack through the following methods: conducting malicious operations by exploiting a zero-day vulnerability in a third-party product; on September 25 using an internal employee identity to gain unauthorized access to a third-party product management platform; obtaining and using a customized withdrawal tool designed for the wallet withdrawal logic; on-chain activity began on September 25 02: 31(UTC+8),the attacker transferred assets across multiple blockchains within approximately 2 hours 52 minutes; the attacker subsequently attempted to tamper with withdrawal records and triggered an additional BTC withdrawal. SlowMist said that it is still investigating how the attacker moved laterally between the affected systems.
Original link https://m.theblockbeats.info/flash/369704
Key points
01
Bitget has commissioned the SlowMist security team to investigate September 25 the hot wallet asset theft incident.
02
As of September 29, the SlowMist investigation found that the incident involved a third-party security product, malicious activity on wallet application hosts, and a withdrawal tool custom-developed by the attacker.
03
The investigation said that the attacker conducted malicious operations by exploiting a zero-day vulnerability in a third-party product.
04
The investigation said that the attacker, on September 25 used an internal employee identity to gain unauthorized access to a third-party product management platform.
05
The attacker obtained and used a customized withdrawal tool designed for the wallet withdrawal logic.
06
On-chain activity began on September 25 02: 31(UTC+8); the attacker transferred assets across multiple blockchains within approximately 2 hours 52 minutes.
07
The attacker subsequently attempted to tamper with withdrawal records and triggered an additional BTC withdrawal.
08
SlowMist said it is still investigating how the attacker moved laterally between the affected systems.
AI-assisted interpretation
The following is analysis, separate from reported facts. Verify important claims independently.
This means the attackers may have simultaneously exploited vulnerabilities in third-party security products, internal employee identities, and specially designed withdrawal tools to transfer hot-wallet assets to multiple blockchains. What has currently been disclosed is the progress of the investigation, not a complete conclusion.
Why it matters to readers
The incident involved hot wallets, a management platform, and the withdrawal process, indicating that multiple system components may have been affected; the findings of the ongoing investigation will determine the specific scope of the impact.
Use Bitget Users should follow the investigation conclusions, scope of impact, and asset disposition statements subsequently published by the platform or SlowMist, and should not determine whether their personal assets are affected based solely on the limited information currently available.
Risks and unknowns
The investigation is ongoing.
It remains unclear how the attackers moved laterally between the affected systems.
The original text does not state the amount of stolen assets.
The original text does not specify the precise scope of impact.
The original text does not disclose the name of the third-party security product.
The original text does not confirm the attackers’ identities.
Related Developments
Loading event timeline…
Related concepts
Hot Wallet
This term is not in the glossary yet. Browse related concepts in the glossary.