BlockBeats news, September 30: SlowMist has issued a statement that Bitget has commissioned the SlowMist security team to investigate the hot wallet asset theft incident that occurred on September 25.
As of September 29, SlowMist's investigation found that the attack involved a third-party security product, malicious activity on the wallet application host, and a withdrawal tool custom-developed by the attacker.
The investigation shows that the attacker mainly carried out the attack through the following methods: exploiting a zero-day vulnerability in a third-party product for malicious operations; on September 25, using an internal employee identity to gain unauthorized access to a third-party product management platform; obtaining and using a customized withdrawal tool designed for the wallet's withdrawal logic; on-chain activity began at 02:31 on September 25 (UTC+8), with the attacker moving assets across multiple blockchains in approximately 2 hours and 52 minutes; subsequently attempting to tamper with withdrawal records and triggering additional BTC withdrawals. SlowMist stated that it is still continuing to investigate how the attacker moved laterally between the affected systems.

