SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit

SlowMist identified malicious activity weeks before the Bitget theft, involving a zero-day vulnerability, two security products and a custom withdrawal tool.

SlowMist traced the earliest logged malicious activity linked to Bitget’s $388 million theft to Aug. 31, when an attacker exploited a zero-day vulnerability affecting a third-party security product.

Attackers stole the funds from Bitget’s hot wallets on Sept. 24 (UTC), transferring assets to addresses they controlled across several blockchains. SlowMist’s investigation identified malicious activity involving two third-party security products and a wallet application host.

According to a SlowMist progress report, the attacker used a hidden script to access the database of what SlowMist called “Product A,” after retrieving its password from an environment variable. Similar activity was later detected on two other nodes on Sept. 23 and Sept. 25. The dates and times in the report are in UTC+8.

Read more

Go to Source

Leave a Reply

Your email address will not be published. Required fields are marked *

Please enter CoinGecko Free Api Key to get this plugin works.