
SlowMist: Bitget Hack Originated from Aug. 31 Zero-Day Exploit
Vexoda Newsroom
Security firm SlowMist has traced the massive Bitget exchange hack, which saw $388 million stolen, to a zero-day exploit on August 31st, affecting a third-party security product.
Security researchers at SlowMist have pinpointed the earliest signs of malicious activity related to the Bitget exchange hack to August 31st, weeks before the actual theft occurred. Their investigation suggests that attackers exploited a "zero-day" vulnerability, which is a previously unknown security flaw, in a third-party security product. This initial exploit appears to have provided the attackers with a crucial foothold, enabling further malicious actions that culminated in the large-scale fund diversion on September 24th. The security firm's detailed report outlines a sophisticated chain of events leading up to the breach.
The primary actors involved in this incident are the cryptocurrency exchange Bitget, the cybersecurity firm SlowMist, and the unidentified attackers. SlowMist's analysis uncovered that the hackers utilized a combination of two compromised third-party security products and a custom-built withdrawal tool. The initial exploit on August 31st reportedly involved retrieving a password from an environment variable to access the database of "Product A." Subsequently, on September 23rd and 25th, similar activities were observed on other nodes, indicating escalating access and control.
To understand the context, a zero-day exploit targets a software vulnerability that is unknown to the software developer, leaving it without a patch. Bitget's hot wallets, which hold readily accessible funds for trading, were the target on September 24th. The attackers leveraged compromised credentials, obtained through the initial exploit, to bypass security measures. This allowed them to issue fraudulent withdrawal commands and transfer the substantial sum to their own controlled addresses across multiple blockchain networks. Bitget's CEO, Gracy Chen, confirmed that the exchange's private keys and cold wallets, which store the majority of funds offline, remained secure.
Following the identification of the breach, Bitget reported that approximately $387.5 million was moved to attacker-controlled addresses. The on-chain verification by SlowMist detailed the initial transfers at 2:31 AM UTC+8 on September 25th, with small amounts of TRX and Ether being moved, followed by a broader wave of transfers over nearly three hours across various blockchains. The attackers' attempts extended to altering withdrawal records directly within the wallet database and even initiating Bitcoin withdrawal requests, though some of these were ultimately unsuccessful due to system errors.
This incident highlights the critical importance of supply chain security for financial platforms. The reliance on third-party software, even for security purposes, introduces potential attack vectors that can have devastating consequences. The sophistication of the attack, including the use of a custom withdrawal tool designed to manipulate risk-control parameters and forge withdrawal requests, underscores the advanced capabilities of threat actors. The implication for the broader market is a renewed focus on the security practices of centralized exchanges and the vendors they partner with.
Moving forward, traders and analysts will be closely monitoring Bitget's ongoing efforts to recover the stolen assets, though the exchange's CEO has expressed limited optimism for a full recovery. Attention will also be directed towards how Bitget and other exchanges enhance their security protocols, particularly concerning third-party integrations and internal credential management. Furthermore, the ongoing investigation by SlowMist into the attackers' movement between systems and their ultimate targets will be crucial in understanding the full scope of the breach and preventing future incidents of this nature.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.