Article

SlowMist Discloses Bitget Investigation update on hot wallet theft; attack involved a vulnerability in a third-party security product

BlockBeats reports that September 30, SlowMist published a statement saying that Bitget has commissioned the SlowMist security team to investigate the hot wallet asset theft incident September 25.

As of September 29, the SlowMist investigation found that the attack involved a third-party security product, malicious activity on wallet application hosts, and a withdrawal tool custom-developed by the attacker.

The investigation showed that the attacker primarily carried out the attack through the following methods: conducting malicious operations by exploiting a zero-day vulnerability in a third-party product; on September 25 using an internal employee identity to gain unauthorized access to a third-party product management platform; obtaining and using a customized withdrawal tool designed for the wallet withdrawal logic; on-chain activity began on September 25 02: 31(UTC+8),the attacker transferred assets across multiple blockchains within approximately 2 hours 52 minutes; the attacker subsequently attempted to tamper with withdrawal records and triggered an additional BTC withdrawal. SlowMist said that it is still investigating how the attacker moved laterally between the affected systems.

Original link https://m.theblockbeats.info/flash/369704