{"id":78861,"date":"2026-09-30T08:02:11","date_gmt":"2026-09-30T08:02:11","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/bitget-hackers-were-inside-the-exchange-for-25-days-before-388m-heist\/"},"modified":"2026-09-30T08:02:11","modified_gmt":"2026-09-30T08:02:11","slug":"bitget-hackers-were-inside-the-exchange-for-25-days-before-388m-heist","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/bitget-hackers-were-inside-the-exchange-for-25-days-before-388m-heist\/","title":{"rendered":"Bitget Hackers Were Inside the Exchange for 25 Days Before $388M Heist"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Slowmist traced the first malicious activity in Bitget-linked systems to Aug. 31, 25 days before the theft.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">An employee identity and a custom withdrawal tool let attackers move funds for 2 hours and 52 minutes.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Mistrack flagged suspected North Korean scripts on Sept. 30 routing loot via CoW Protocol and Chainflip.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2>The Door Was Open Since August<\/h2>\n<p>Bitget brought in the blockchain security firm on Sept. 25 to investigate the theft from its hot wallets, and the findings, current as of Sept. 29, <a href=\"https:\/\/github.com\/slowmist\/Knowledge-Base\/blob\/master\/open-report-V2\/incident-response\/SlowMist%20Investigation%20Progress%20Report%20-%20Bitget_zh-cn.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">reshape the timeline<\/a>. The earliest malicious activity in the available logs dates to Aug. 31, when a service on one node of a third-party security product, which Slowmist calls \u201cProduct A,\u201d was hit through a zero-day vulnerability, meaning a software flaw its vendor did not yet know existed.<\/p>\n<p>The attacker ran a hidden script, read an environment variable holding a database password and connected to the database. The same hidden-script activity showed up on two more nodes on Sept. 23 and Sept. 25, with the report adding:<\/p>\n<blockquote>\n<p>These findings show that the affected service environments had already been compromised before the assets were transferred out.<\/p>\n<\/blockquote>\n<p>That fits Bitget\u2019s own explanation that attackers abused <a href=\"https:\/\/news.bitcoin.com\/exchanges\/bitget-restarts-bitcoin-withdrawals-388m-hack-investigation-widens\/\">a third-party security product<\/a> to obtain high-level internal credentials. What Slowmist added is the part nobody knew, i.e. how long the intruders had been sitting there.<\/p>\n<h2>The Night of the Theft, Minute by Minute<\/h2>\n<p>The report logs every step in UTC+8. Converted to UTC, the sequence on Sept. 24 runs like this:<\/p>\n<ul>\n<li style=\"font-weight:400\" aria-level=\"1\"><b>16:07 UTC:<\/b> Using an internal employee\u2019s identity, the attacker entered the management platform of a second vendor tool, \u201cProduct B,\u201d and made three straight attempts to inject system commands.<\/li>\n<li style=\"font-weight:400\" aria-level=\"1\"><b>17:49 UTC:<\/b> A \u201chighly customized withdrawal tool,\u201d later recovered from files the attacker deleted, began executing the theft. It forged risk-control parameters, built withdrawal requests and triggered the withdrawal process itself.<\/li>\n<li style=\"font-weight:400\" aria-level=\"1\"><b>18:31 UTC:<\/b> The first verified onchain transfer landed, 93 TRX, followed 11 seconds later by 0.84 ETH.<\/li>\n<li style=\"font-weight:400\" aria-level=\"1\"><b>21:23 UTC:<\/b> The last compiled transfer, about 2 hours and 52 minutes after the first.<\/li>\n<\/ul>\n<p>The heaviest stretch came early, as Arkham Intelligence found that <a href=\"https:\/\/news.bitcoin.com\/featured\/bitget-hackers-drain-228m-in-18-minutes-arkham-tracks-7-chains\/\">$228 million left<\/a> in just 18 minutes across seven chains, with XRP worth about $153 million as the single largest piece. After the transfers started, the attacker also tried to rewrite withdrawal records in the wallet database. Two fabricated BTC withdrawal orders returned errors, and the logs show the intruder checking order status and trying again.<\/p>\n<p>No private keys were taken, but instead, the attackers <a href=\"https:\/\/fortune.com\/2026\/09\/25\/north-korea-bitget-387-million-crypto-attack\/\" target=\"_blank\" rel=\"noopener noreferrer\">tricked the internal approval<\/a> system into signing off on transfers that looked legitimate.<\/p>\n<h2>The Side Door Through Chainflip<\/h2>\n<p>The money is still moving, with Slowmist founder Cos saying Mistrack\u2019s Trackagent tool caught suspected North Korean hackers <a href=\"https:\/\/panews.io\/articles\/01a0f044-6af4-715a-96af-8fe39a419428\" target=\"_blank\" rel=\"noopener noreferrer\">combining CoW Protocol and Chainflip<\/a> to launder the funds. Automated scripts place swap orders on CoW Protocol, a decentralized exchange (DEX) aggregator, and set the recipient to <a href=\"https:\/\/www.techflowpost.com\/en-US\/newsletter\/138342\" target=\"_blank\" rel=\"noopener noreferrer\">a pre-configured Chainflip<\/a> deposit contract. Once an order settles, the assets roll straight into a cross-chain swap and come out the other side as bitcoin.<\/p>\n<p>The irony, however, is hard to miss because just one day earlier, Chainflip brokers rejected a direct deposit from the same attackers and sent the funds back along their original route. Cos warned that Chainflip\u2019s anti-money laundering (AML) and know-your-transaction (KYT) checks <a href=\"https:\/\/www.techflowpost.com\/en-US\/newsletter\/138187\" target=\"_blank\" rel=\"noopener noreferrer\">lag behind the hackers<\/a>, whose system splits funds across bridges, swaps into bitcoin, mixes it and pivots the moment a route closes.<\/p>\n<p>Other doors have been slammed shut too. Near Intents blocked most of a <a href=\"https:\/\/news.bitcoin.com\/featured\/near-intents-slams-door-50m-bitget-hack-laundering-flows\/\">$50 million laundering attempt<\/a>, letting $166,000 through and freezing $503,000. Earlier flows ran through Thorchain, Uniswap, 1inch Fusion and Stargate, which reopened <a href=\"https:\/\/news.bitcoin.com\/crypto-news\/thorchain-faces-heat-as-bitget-hack-revives-bybit-controversy\/\">an old Thorchain fight<\/a> over whether neutral protocols should police stolen money.<\/p>\n<h2>What Bitget Users Should Still Know<\/h2>\n<p>Bitget says its User Protection Fund, holding more than $464 million, covers the loss. Withdrawals are <a href=\"https:\/\/news.bitcoin.com\/exchanges\/bitget-restarts-bitcoin-withdrawals-388m-hack-investigation-widens\/\">coming back in stages,<\/a> with bitcoin first followed by ether, USDT and then all other assets.<\/p>\n<p>The bigger question sits outside Bitget and Slowmist did not name the vendors behind \u201cProduct A\u201d and \u201cProduct B,\u201d and it says it is still working out how the attacker moved between systems. North Korea-linked groups stole a record <a href=\"https:\/\/fortune.com\/2026\/09\/25\/north-korea-bitget-387-million-crypto-attack\/\" target=\"_blank\" rel=\"noopener noreferrer\">$2 billion in 2025<\/a>, per Fortune, so any exchange running the same security stack now has a reason to comb its own logs back to the end of August.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/bitget-hack-slowmist-25-days-chainflip-cow-protocol\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Slowmist traced the first malicious activity in Bitget-linked systems to Aug. 31, 25 days before the theft. An employee identity and a custom withdrawal tool let attackers move funds for 2 hours and 52 minutes. Mistrack flagged suspected North Korean scripts on Sept. 30 routing loot [&hellip;]<\/p>\n","protected":false},"author":3947362404,"featured_media":78862,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78861"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/3947362404"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=78861"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78861\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/78862"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=78861"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=78861"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=78861"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}