Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
SlowMist said its investigation into the wallet asset theft that occurred on Sept. 25 at Bitget’s request found signs that a zero-day vulnerability in a system used by an external security vendor was exploited.
A zero-day vulnerability refers to an undisclosed flaw for which no security patch has yet been released. SlowMist said the attacker appears to have gained unauthorized access to the external security vendor’s management system by posing as an internal employee. It also found signs the attacker used a separately developed withdrawal tool to remove assets from the Bitget wallet.
The attack began at 6:31 p.m. UTC on Sept. 24 and continued across multiple blockchains for about two hours and 52 minutes. SlowMist added that the attacker later manipulated withdrawal records and attempted additional BTC withdrawals. The firm said it is continuing to investigate the specific intrusion route.