Bitget hack linked to zero-day exploit dating back to August
Security firm SlowMist reports that the Bitget hack, which resulted in approximately $388 million in unauthorized transfers on September 24, began as early as August 31. The investigation suggests attackers exploited a zero-day vulnerability in a third-party security product, identified as "Product A," to gain database access. Further malicious activity was detected on September 23 and 25, including an attempt to compromise a second external system, "Product B," by impersonating an employee. The attackers utilized a custom tool designed to manipulate withdrawal processes, bypass risk controls, and issue fraudulent orders over a period of nearly three hours.
Summaries are written by AI from the original article. Not investment advice.