Bitget Hackers Were Inside the Exchange for 25 Days Before $388M Heist
(Originally posted on : Bitcoin News )
Key Takeaways
- Slowmist traced the first malicious activity in Bitget-linked systems to Aug. 31, 25 days before the theft.
- An employee identity and a custom withdrawal tool let attackers move funds for 2 hours and 52 minutes.
- Mistrack flagged suspected North Korean scripts on Sept. 30 routing loot via CoW Protocol and Chainflip.
The Door Was Open Since August
Bitget brought in the blockchain security firm on Sept. 25 to investigate the theft from its hot wallets, and the findings, current as of Sept. 29, reshape the timeline. The earliest malicious activity in the available logs dates to Aug. 31, when a service on one node of a third-party security product, which Slowmist calls “Product A,” was hit through a zero-day vulnerability, meaning a software flaw its vendor did not yet know existed.
The attacker ran a hidden script, read an environment variable holding a database password and connected to the database. The same hidden-script activity showed up on two more nodes on Sept. 23 and Sept. 25, with the report adding:
These findings show that the affected service environments had already been compromised before the assets were transferred out.
That fits Bitget’s own explanation that attackers abused a third-party security product to obtain high-level internal credentials. What Slowmist added is the part nobody knew, i.e. how long the intruders had been sitting there.
The Night of the Theft, Minute by Minute
The report logs every step in UTC+8. Converted to UTC, the sequence on Sept. 24 runs like this:
- 16:07 UTC: Using an internal employee’s identity, the attacker entered the management platform of a second vendor tool, “Product B,” and made three straight attempts to inject system commands.
- 17:49 UTC: A “highly customized withdrawal tool,” later recovered from files the attacker deleted, began executing the theft. It forged risk-control parameters, built withdrawal requests and triggered the withdrawal process itself.
- 18:31 UTC: The first verified onchain transfer landed, 93 TRX, followed 11 seconds later by 0.84 ETH.
- 21:23 UTC: The last compiled transfer, about 2 hours and 52 minutes after the first.
The heaviest stretch came early, as Arkham Intelligence found that $228 million left in just 18 minutes across seven chains, with XRP worth about $153 million as the single largest piece. After the transfers started, the attacker also tried to rewrite withdrawal records in the wallet database. Two fabricated BTC withdrawal orders returned errors, and the logs show the intruder checking order status and trying again.
No private keys were taken, but instead, the attackers tricked the internal approval system into signing off on transfers that looked legitimate.
The Side Door Through Chainflip
The money is still moving, with Slowmist founder Cos saying Mistrack’s Trackagent tool caught suspected North Korean hackers combining CoW Protocol and Chainflip to launder the funds. Automated scripts place swap orders on CoW Protocol, a decentralized exchange (DEX) aggregator, and set the recipient to a pre-configured Chainflip deposit contract. Once an order settles, the assets roll straight into a cross-chain swap and come out the other side as bitcoin.
The irony, however, is hard to miss because just one day earlier, Chainflip brokers rejected a direct deposit from the same attackers and sent the funds back along their original route. Cos warned that Chainflip’s anti-money laundering (AML) and know-your-transaction (KYT) checks lag behind the hackers, whose system splits funds across bridges, swaps into bitcoin, mixes it and pivots the moment a route closes.
Other doors have been slammed shut too. Near Intents blocked most of a $50 million laundering attempt, letting $166,000 through and freezing $503,000. Earlier flows ran through Thorchain, Uniswap, 1inch Fusion and Stargate, which reopened an old Thorchain fight over whether neutral protocols should police stolen money.
What Bitget Users Should Still Know
Bitget says its User Protection Fund, holding more than $464 million, covers the loss. Withdrawals are coming back in stages, with bitcoin first followed by ether, USDT and then all other assets.
The bigger question sits outside Bitget and Slowmist did not name the vendors behind “Product A” and “Product B,” and it says it is still working out how the attacker moved between systems. North Korea-linked groups stole a record $2 billion in 2025, per Fortune, so any exchange running the same security stack now has a reason to comb its own logs back to the end of August.