The attackers behind the $387.5 million Bitget breach held a foothold inside parts of the exchange's infrastructure for almost four weeks before any funds moved, according to interim forensic findings released September 30 by SlowMist and Mandiant, the two security firms Bitget hired in the hours after the September 24 theft.

The central finding: no private keys were stolen. The attacker compromised third-party security products — in one case through a zero-day vulnerability — moved into Bitget's wallet environment, and used a custom-built withdrawal tool to issue transfers the exchange's own systems accepted as valid. Both firms described their findings as interim, and neither named the affected vendors. SlowMist published a progress report; the details were corroborated by independent reporting on both firms' findings.

The Timeline, Reconstructed

All times UTC, converted from the UTC+8 timestamps in SlowMist's report.

August 31 — the foothold. On a node of a system SlowMist calls only "Product A," the attacker exploited a zero-day to run a hidden script under the service process, read a database password from an environment variable, and connect to the database. Similar hidden-script activity appeared on two other nodes on September 23 and 25 — evidence the environment was already compromised long before the theft.

September 24, ~16:07 — lateral movement. The attacker entered a second system, "Product B," using an internal employee's identity. Task parameters were spliced with system commands; code submitted through a web execution interface attempted to change server configuration, place relay files and assemble malware in pieces.

~17:49 — the tool deploys. SlowMist recovered, from deleted files, a highly customized tool that forged withdrawal parameters and invoked Bitget's own withdrawal process.

18:31–21:23 — the theft. The first verified on-chain outflow was 93 TRX to an attacker address, followed 11 seconds later by 0.84 ETH. Transfers continued across multiple blockchains for about two hours and 52 minutes.

After 21:22 — the failed encore. Logs show attempts to edit withdrawal records in the wallet database and two forged Bitcoin withdrawal orders that errored out. The attacker reviewed logs, checked order status and made further attempts.

What It Means

The findings formalize what Bitget's CEO suggested last week, with two additions that matter beyond this incident.

First, dwell time. Twenty-four days passed between the earliest malicious activity and the first unauthorized transfer — a window in which the intrusion was live but undetected. Exchange security programs that measure themselves by response speed after funds move are measuring the wrong thing if the adversary is already inside for a month.

Second, the attack surface is the security stack itself. A zero-day in a product deployed to defend the exchange became its point of failure, and privileged employee identity was the bridge between systems. Attribution remains open: North Korean involvement is suspected but unconfirmed, and both firms say their work continues on how the attacker moved between the compromised systems.

Bitget CEO Gracy Chen, speaking on Cointelegraph's Chain Reaction, said she is "not very optimistic" about fully recovering the roughly $388 million, pointing to the limited recovery from Bybit's 2025 hack as the realistic reference point.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.