Slow Mist Releases Interim Investigation Report on Bitget Incident, Early Malicious Activities Traceable to August 31

By: x.com|09/30/2026 04:58:55

On September 30, Slow Mist founder Yuxian released an interim investigation report on the Bitget incident on social media.

The report states that the attackers allegedly hacked two third-party security products and wallet business hosts in succession, and initiated cross-chain asset transfers through highly customized withdrawal tools. It indicates that the investigation is ongoing as of September 29, and how the attackers completed specific infiltrations across multiple systems remains to be further confirmed.

The investigation shows that the earliest malicious activity can be traced back to August 31. At that time, a node server of third-party security product A had a zero-day vulnerability, and the attackers ran hidden scripts under the service process, attempting to read database passwords, environment variables, and connect to the database. On September 23 and September 25, similar hidden script activities occurred on two other nodes, indicating that the relevant service environment may have been infiltrated before the assets were transferred out.

In the early hours of September 25, the attackers allegedly impersonated internal employee accounts to access the management platform of security product B, and starting from 00:07, they repeatedly concatenated system commands in the task parameters, attempting to write malicious files. Subsequently, the attackers submitted code through the platform's web execution entry, trying to modify server configurations, write communication relay files, and upload and assemble malicious programs in batches.

It is reported that a customized tool developed for wallet withdrawal logic was recovered from the files deleted by the attackers. This tool forges withdrawal parameters, constructs withdrawal requests, and invokes the withdrawal process. Host logs show that the relevant malicious program began running at 01:49 on September 25.

On-chain records indicate that the first verified transfer occurred at 02:31 on September 25, with the attacker's address first receiving 93 TRX, followed by 0.84 ETH 11 seconds later; the related transfers continued until 05:23 that day, lasting approximately 2 hours and 52 minutes, involving multiple blockchain networks. After the funds began to flow out, the attackers also attempted to directly modify the withdrawal records in the wallet database and invoke local withdrawal tasks; the logs contain records of two forged BTC orders that reported errors after business processing, with the related attempts occurring after 05:22.

This disclosure indicates that the attack path may cover third-party security services, management platforms, wallet hosts, and withdrawal business processes. The identity of the attackers has not yet been disclosed, nor has the scale of the final losses and the scope of affected systems been specified.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]