The prominent blockchain security firm SlowMist has released a comprehensive phased investigation report regarding the recent security breach at Bitget, a major cryptocurrency exchange. The findings, published on September 29, 2026, reveal that the exploit targeted the platform's hot wallets by leveraging a zero-day vulnerability in an undisclosed third-party security product. While the primary attack occurred on September 25, forensic analysis indicates that the threat actors began their malicious operations as early as August 31, suggesting a prolonged period of reconnaissance and preparation.
Mechanism of the Exploit and Unauthorized Access
According to the SlowMist report, the attackers gained unauthorized access to a management platform for a third-party security product used by the exchange. By impersonating internal employees, the malicious actors were able to bypass standard protocols and manipulate the environment. The investigation highlights that the breach was not a direct failure of the exchange's core infrastructure, but rather a compromise of the supply chain involving external software dependencies.
The technical details of the incident include:
- Exploitation of a previously unknown zero-day flaw in a third-party service provider.
- Unauthorized entry into the management interface on September 25.
- The deployment of a highly customized withdrawal tool specifically engineered to interact with the wallet system's internal withdrawal logic.
Timeline of On-Chain Activity
The execution phase of the theft commenced at 02:31 UTC on September 25. SlowMist reports that the attackers utilized their custom tools to automate the siphoning of assets across multiple blockchain networks. The window of active exploitation lasted approximately two hours, during which time a variety of digital assets were transferred to attacker-controlled addresses. The sophisticated nature of the withdrawal tool suggests that the perpetrators had extensive knowledge of the exchange's internal architecture, likely gained during the month-long period following the initial breach in late August.
The earliest malicious activity can be traced back to August 31st, with malicious activities exploiting a zero-day vulnerability in a certain third-party product; on September 25th, someone accessed the third-party product management platform without authorization, posing as an internal employee.
The Bitget incident underscores the persistent risks associated with third-party integrations within the cryptocurrency ecosystem. As the investigation continues, the focus remains on tracking the movement of stolen funds across different chains and identifying the specific third-party product involved to prevent further exploits. This event serves as a critical reminder for VASP (Virtual Asset Service Providers) to conduct rigorous audits not only of their own code but also of the third-party security layers that form part of their operational stack.
Frequently Asked Questions
Quick answers to the most common questions about this topic.