
On September 25, 2026, the cryptocurrency exchange Bitget reached out to SlowMist to investigate the theft of assets from hot wallets. As of September 29, experts identified malicious activity related to two third-party security products, referred to as Product A and Product B. The initial malicious activity was recorded on August 31, when the attacker exploited a zero-day vulnerability in the Product A system. They executed a hidden script that helped them gain access to the database. The reuse of malicious scripts was recorded on two more nodes of Product A on September 23 and 25. The report notes that the environments of these services were compromised before the active asset theft began.
On September 25, the attacker also gained access to the management platform of Product B. Using the credentials of an internal employee, they attempted three times to inject commands into the job parameters to write malicious files and alter server configurations. SlowMist recovered deleted files, among which was a tool for asset withdrawal. This tool modified risk control parameters and initiated fund withdrawal operations. In the first operation, 93 TRX was transferred to the blockchain, followed by another 0.84 ETH after 11 seconds. Asset transfers continued for 2 hours and 52 minutes and occurred across multiple blockchains.
The attacker continued to attempt to modify withdrawal records in the database and launched new orders. Some of these, including two fake bitcoin withdrawal orders, were not successfully processed. The SlowMist report does not specify the total amount of stolen assets, the complete list of tokens, or the identifiers of the products involved. The investigation into how the attacker moved between systems is still ongoing.




