NEW: A wallet linked to Ethereum co-founder and Consensys CEO Joseph Lubin transferred a total of
Binance Shifts Value Transfers to Solana from Tron and Ethereum
Micron Technology Projects $61.5 Billion Revenue for Q1 of Fiscal Year 2027
Base Completes Third Mainnet Upgrade with New Features
Binance Futures to Delist PROMPT and Other USDT-Margined Perpetual Contracts
277,162,705 $USDT (276,995,853 USD) transferred from #Binance to unknown wallet...
Hut 8's acquisition of Poolin's Texas Bitcoin mining facility assets reopens bidding, valued at up to $180 million
Analyst: ADA still faces selling pressure after 10% weekly drop, $0.24 becomes key support
DogeOS Launches Public Testnet for Dogecoin-Based Applications
Saylor Says Strategy, Strive Can Win Share of $318.5T With Bitcoin
1,200 $BTC (100,347,670 USD) transferred from #Binance to #Kraken...
Micron CEO: Memory market supply-demand will be tighter in 2027-2028 than 2026; FY2027 Q1 revenue to reach $61.5 billion
Grayscale's Zcash ETF completes "3-for-1" share split, trading on split-adjusted basis from today
Orca CLO Christopher Montagano said at Korea Blockchain Week 2026 that SEC's
Whale 0xe271 bought 39,018 $AAVE ($6.3M) from #Kraken 4 hours...
AI-native cloud platform GMI Cloud completes $668 million financing, with NVIDIA participating
Florida Court Orders Fundsz Promoters to Pay Over $30 Million in Fraud Case
ether.fi: Earlier Ethereum Node Operator Security Incident Did Not Affect weETH, User Funds Are Safe
Ethereum Whale Transfers $356 Million Worth of ETH to New Address
New Bitcoin upgrade catches hidden key leaks hiding the exact fix
An address "bought the dip" early this morning, purchasing 1,486.37 ETH and now sitting on a $33,000 loss
1,200 $BTC (100,268,411 USD) transferred from #Kraken to #Binance...
Wallet linked to Ethereum co-founder Joseph Lubin transfers 133,298 ETH to a new wallet
A wallet linked to #Ethereum co-founder Joseph Lubin(@ethereumJoseph) transferred 133,298 $ETH...
1,200 $BTC (100,314,837 USD) transferred from #Binance to #Kraken...
Grayscale: XRP’s Near-6% Bitcoin Valuation Sets a Benchmark for Zcash
Cardano Hits $0.25 on Petrobras Adoption: Next ADA Buy Zone Revealed
Ancient Ethereum whale moves $356 million worth of ETH to a new address
Bybit Releases 40th Proof-of-Reserves ReportBybit released its 40th proof-of-reserves report based...
A whale withdrew 39,018 AAVE worth $6.2 million from Kraken 3 hours ago
Bybit Reports $19.6 Billion in Proof-of-Reserves Following Expansion of Asset Coverage
Morgan Stanley's total Bitcoin holdings surpass 10,000 BTC for the first time, worth over $870 million
CFTC seeks to define event contracts as swaps amid prediction market fight
514,175 $HYPE (46,282,266 USD) transferred from #HyperCore to #Kinetiq...
Robinhood CEO on stock token roadmap: Covering thousands of companies and exploring private equity tokenization
156,300,000 $USDC (156,362,520 USD) transferred from Unknown Whale 1 to #Aave...
Cryptocurrency Market Financing Reaches $1.114 Billion in September 2026
400,000,000 $XRP (595,636,565 USD) unlocked at #Ripple...
Solana treasury company HSDT completes $15 million share offering, to buy more SOL or repurchase shares
ESMA proposes expanding MiCA scope to cover DeFi entry points, staking and crypto lending services
U.S. SEC Files Lawsuits Against Two Private Equity Funds for Fraudulent Practices
Ripple Unlocks 1 Billion XRP Valued at Approximately 1.49 Billion USD
Hyperliquid dev team HyperLabs address requests redemption of 3.75 million HYPE
200,000,000 $XRP (297,818,282 USD) unlocked at #Ripple...
Uphold Adds XRP, Bitcoin Inheritance, Citing $331 Billion Stranded
TD Cowen says Bitcoin is evolving from an asset into a capital markets...
Spot silver falls below the $60 mark
Arthur Hayes: Hyperliquid Is the Best DEX, but Not Necessarily the Most Profitable InvestmentFlop...
MetaMask exits Lido validators as it investigates security incident
300,000,000 $XRP (446,727,424 USD) unlocked at #Ripple...
MetaMask Staking Withdraws from Lido Validators Following Security Breach
Ripple Unlocks 1 Billion XRP in One Go, Worth About $1.49 Billion
MetaMask said it has identified a security incident affecting part of its
KLEA Crypto Daily: Wednesday, September 30, 2026
MetaMask: Security Incident Affects Part of Infrastructure, No Immediate Threat to Wallets...
AvengerDAO Security Marketplace Expands to 17 Firms with New Additions
100,000,000 $XRP (148,909,141 USD) unlocked at #Ripple...
Fed's Kashkari: Expects one more rate hike this year and another in 2027
METAMASK CURRENTLY RESPONDING TO ONGOING SECURITY INCIDENT, SAYS THERE IS NO THREAT TO WALLETS:...
Aave Founder: Closely Monitoring MetaMask Staking Incident, Aave Markets Unaffected
Lido: MetaMask Staking to exit its operated validator nodes, expected to complete before October 7, 2026
MetaMask Staking Exits Lido Validators Amid Security Concerns
1,611 $BTC (134,647,322 USD) transferred from #Kraken to unknown wallet...
METAMASK RESPONDING TO SECURITY INCIDENT; NO THREAT TO METAMASK WALLET AND METAMASK CURRENTLY...
156,300,000 $USDC (156,330,400 USD) transferred from #Aave to Unknown Whale 1...
MSCI Rule Puts Strategy at Risk, Says Bitcoin Policy Institute Paper
NEAR Traders on Hyperliquid Face Significant Losses Amid Market Rally
Gemini 4 Is Here, and Google’s Flagship Tops All Other AI Models on Cybersecurity
Robinhood to Launch Crypto Perpetual Futures in the US
SlowMist Revealed Details of the Attack on Bitget’s Hot Wallets
- SlowMist found that malicious activity linked to two third-party security products was detected in Bitget’s systems before the asset theft.
- The attacker exploited a zero-day in one product and also gained access to another system using an employee’s credentials.
On September 25, 2026, crypto exchange Bitget brought in SlowMist to investigate the theft of assets from its hot wallets. As of September 29, the specialists identified malicious activity linked to two third-party security products, labeled in the report as Product A and Product B.
SlowMist determined that the earliest detected malicious activity occurred on August 31 on one of Product A’s nodes. The service was compromised via a zero-day vulnerability. The attacker then launched a stealth script within the service process, ran a command to read an environment variable containing the database password, and connected to it.
Researchers recorded similar activity involving stealth scripts on two more Product A nodes — on September 23 and September 25. The report notes that the environments of these services had been compromised even before the asset outflows began.
On the morning of September 25, the attacker also gained access to Product B’s management platform using an internal employee account. They attempted three times to inject system commands into Product B task parameters to write malicious files.
After that, via the command execution endpoint in the platform’s web interface, the attacker tried to change the server configuration, write a file to relay communications, and download and compile malicious program files in batches.
One of the key outcomes of the investigation was the recovery of files deleted by the attacker. Among them, SlowMist found a purpose-built asset-draining tool tailored to the wallet system’s logic.
The tool spoofed risk control parameters, generated withdrawal requests, and triggered the corresponding procedure. According to host logs, the malware began operating and carrying out the theft of crypto assets on the night of September 25.
As part of the first blockchain transfer confirmed by SlowMist, the attacker’s address received 93 TRX. Eleven seconds later, an address on the Ethereum network received 0.84 ETH. Confirmed asset transfers lasted about 2 hours and 52 minutes and took place across multiple blockchains.
After the transfers began, the attacker also tried to directly modify withdrawal records in the wallet’s database and run withdrawal jobs locally on the host. Logs showed that two fabricated bitcoin withdrawal orders entered processing, but both ended in errors.
After that, the attacker reviewed logs, checked the status of orders, and made new withdrawal attempts.
SlowMist’s report does not specify the total amount of stolen assets, the full list of tokens, the names of Product A and Product B, or the identity of the attacker or group behind the incident. The company also did not determine the definitive initial compromise vector for the entire system.
Separately, SlowMist noted that, at the time of preparing the report, the investigation into how the attacker moved between the involved systems was still ongoing.
Read more about the Bitget hack — in the article:
Сообщение SlowMist Revealed Details of the Attack on Bitget’s Hot Wallets появились сначала на INCRYPTED.
Source: Incrypted
