SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit
SlowMist identified malicious activity weeks before the Bitget theft, involving a zero-day vulnerability, two security products and a custom withdrawal tool.
Asanat Analysis — Why it matters
SlowMist's forensic timeline—tracing malicious activity to August 31 via zero-day exploitation—indicates the Bitget incident was not opportunistic but part of a sustained attack chain. The involvement of compromised security products suggests either supply-chain infiltration or security tool misconfigurations that created persistence mechanisms. This pattern mirrors previous exchange breaches (FTX, Ronin) where attackers combined technical exploits with internal access vectors.
The discovery of a custom withdrawal tool in the attack infrastructure signals the attacker spent time enumerating Bitget's infrastructure pre-breach, rather than executing a smash-and-grab. This reconnaissance window is critical: it implies other exchanges may face similar zero-day probing without detection. The fact that activity predated the actual theft by weeks underscores the gap between vulnerability discovery and patch deployment in the exchange ecosystem—a systemic risk that affects custody and liquidity providers.