FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.9T -0.2%24h Vol $100.5B -7%Fear & Greed 74/100Alts Index 53/100
BTC.D 58.4% 0%Stable.D 9.2% 0%ETH.D 11.4% 0%Others.D 21.0% 0%
TRAC$0.4763+24.9%•SOON$0.4987+23.8%•NIGHT$0.0400+23.02%•STONK$0.2919+22.27%•STX$0.3752+20.06%•MON$0.0318+18.26%•CAP$0.0698+16.76%•PLUME$0.0202+13.7%•ZBCN$0.00284307+11.62%•WLD$0.5402+10.45%•
AI$0.1811-13.33%•TIBBIR$0.2944-12.76%•2Z$0.0579-12.06%•BTW$1.158-11.27%•BR$0.7593-10.7%•BP$1.207-8.52%•MET$0.3157-7.14%•COMP$24.385-6.9%•GRASS$0.6944-6.21%•MARSCOIN$0.1385-5.46%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      SlowMist Revealed Details of the Attack on Bitget’s Hot Wallets

      • SlowMist found that malicious activity linked to two third-party security products was detected in Bitget’s systems before the asset theft.
      • The attacker exploited a zero-day in one product and also gained access to another system using an employee’s credentials.

      On September 25, 2026, crypto exchange Bitget brought in SlowMist to investigate the theft of assets from its hot wallets. As of September 29, the specialists identified malicious activity linked to two third-party security products, labeled in the report as Product A and Product B.

      SlowMist determined that the earliest detected malicious activity occurred on August 31 on one of Product A’s nodes. The service was compromised via a zero-day vulnerability. The attacker then launched a stealth script within the service process, ran a command to read an environment variable containing the database password, and connected to it.

      Researchers recorded similar activity involving stealth scripts on two more Product A nodes — on September 23 and September 25. The report notes that the environments of these services had been compromised even before the asset outflows began.

      On the morning of September 25, the attacker also gained access to Product B’s management platform using an internal employee account. They attempted three times to inject system commands into Product B task parameters to write malicious files.

      After that, via the command execution endpoint in the platform’s web interface, the attacker tried to change the server configuration, write a file to relay communications, and download and compile malicious program files in batches.

      One of the key outcomes of the investigation was the recovery of files deleted by the attacker. Among them, SlowMist found a purpose-built asset-draining tool tailored to the wallet system’s logic.

      The tool spoofed risk control parameters, generated withdrawal requests, and triggered the corresponding procedure. According to host logs, the malware began operating and carrying out the theft of crypto assets on the night of September 25.

      As part of the first blockchain transfer confirmed by SlowMist, the attacker’s address received 93 TRX. Eleven seconds later, an address on the Ethereum network received 0.84 ETH. Confirmed asset transfers lasted about 2 hours and 52 minutes and took place across multiple blockchains.

      After the transfers began, the attacker also tried to directly modify withdrawal records in the wallet’s database and run withdrawal jobs locally on the host. Logs showed that two fabricated bitcoin withdrawal orders entered processing, but both ended in errors.

      After that, the attacker reviewed logs, checked the status of orders, and made new withdrawal attempts. 

      SlowMist’s report does not specify the total amount of stolen assets, the full list of tokens, the names of Product A and Product B, or the identity of the attacker or group behind the incident. The company also did not determine the definitive initial compromise vector for the entire system.

      Separately, SlowMist noted that, at the time of preparing the report, the investigation into how the attacker moved between the involved systems was still ongoing.

      Read more about the Bitget hack — in the article:

      Сообщение SlowMist Revealed Details of the Attack on Bitget’s Hot Wallets появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud