header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

SlowMist Releases Preliminary Investigation Report on Bitget Incident, Earliest Malicious Activity Traced Back to August 31

BlockBeats news, September 30: SlowMist founder Yu Xian published a phased investigation report on the Bitget incident on social media.


The report states that the attacker is suspected to have successively breached two third-party security products and wallet business hosts, and initiated cross-chain asset transfers through a highly customized withdrawal tool. SlowMist said the investigation was still ongoing as of September 29, and how the attacker completed the specific penetration across multiple systems remains to be further confirmed.


The investigation shows that the earliest malicious activity can be traced back to August 31. At that time, a node server of third-party security product A had a zero-day vulnerability, and the attacker ran hidden scripts under the service process, attempting to read database passwords, environment variables, and connect to the database. On September 23 and September 25, similar hidden script activity appeared on two other nodes, meaning the relevant service environment may have already been compromised before the asset transfer.


In the early hours of September 25, the attacker is suspected to have impersonated an internal employee account to enter the management platform of security product B, and starting at 00:07 repeatedly concatenated system commands into task parameters, attempting to write malicious files. Subsequently, the attacker also submitted code through the platform's web execution entry, attempting to modify server configurations, write communication relay files, and upload and assemble malicious programs in batches.


SlowMist said that from files deleted by the attacker, a set of customized tools developed for wallet withdrawal logic was recovered. The tool would forge withdrawal parameters, construct withdrawal requests, and invoke the withdrawal process. Host logs show that the relevant malicious program began running at 01:49 on September 25.


On-chain records show that the first verified transfer occurred at 02:31 on September 25. The attacker's address first received 93 TRX, and 11 seconds later received 0.84 ETH; the related transfers continued until 05:23 that day, lasting about 2 hours and 52 minutes, involving multiple blockchain networks. After funds began to flow out, the attacker also attempted to directly modify withdrawal records in the wallet database and invoke local withdrawal tasks; the logs contain records of two forged BTC orders erroring after business processing, with the related attempts occurring after 05:22.


This disclosure indicates that the attack path may cover third-party security services, management platforms, wallet hosts, and withdrawal business processes. SlowMist has not yet published the attacker's identity attribution, nor explained the final scale of losses and the scope of affected systems.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish