SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit
What happened
31, when an attacker exploited a zero-day (a flaw already being used in attacks before a fix exists) vulnerability affecting a third-party security product. SlowMist identified malicious activity weeks before the Bitget theft, involving a zero-day vulnerability, two security products and a custom withdrawal tool.
SlowMist traced the earliest logged malicious activity linked to Bitget’s $388 million theft to Aug. Attackers stole the funds from Bitget’s hot wallets on Sept.
24 (UTC), transferring assets to addresses they controlled across several blockchains. SlowMist’s investigation identified malicious activity involving two third-party security products and a wallet application host.
Similar activity was later detected on two other nodes on Sept. The dates and times in the report are in UTC+8.
25, the attacker also accessed the management platform of a second security product, which SlowMist called “Product B,” using an internal employee’s identity. SlowMist said the attacker then attempted to inject system commands, alter server configurations and upload malicious program files. SlowMist said its investigation remains ongoing and that it is still examining how the attacker moved between the affected systems.
Sources & evidence
- Cointelegraph Reporting source
SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit ↗
https://cointelegraph.com/news/bitget-hack-zero-day-slowmist-investigation