SlowMist and Mandiant: Bitget attackers had Aug 31 zero-day foothold before drain
By Crypto Wire
September 30, 2026
SlowMist and Mandiant released interim forensic notes on September 30 that push the Bitget intrusion clock back almost four weeks: the earliest malicious activity they cite is August 31, long before the ~$387.5 million hot/warm-wallet drain window on September 24. Both firms say private keys were not stolen; the path ran through compromised third-party security products—including a zero-day on a system SlowMist labels only as “Product A”—then lateral movement into Bitget’s wallet environment and a recovered custom withdrawal tool that forged instructions the exchange’s own process accepted. This is a new Rug Room chapter after Bitget’s own third-party-product account (9908) and the USDT reopen (10355)—not a silent edit of those URLs.
What SlowMist’s timeline actually prints. Co-founder Yu Xian (Cos) says the August 31 zero-day on a Product A node let a hidden script run under the service process, attempt to read database passwords and environment variables, and connect to the database; similar hidden-script activity showed on two other nodes on September 23 and September 25 (UTC+8). From about 16:07 UTC September 24, an internal employee identity was used against a second system (“Product B”) to splice commands into task parameters and stage malware through a web execution interface. SlowMist recovered, from deleted files, a custom tool that forged withdrawal parameters and called Bitget’s withdrawal process; host malware started around 17:49 UTC.
The on-chain drain clock still matches Bitget’s first detection. First verified outflow at 18:31 UTC September 24: 93 TRX to an attacker address, then 0.84 ETH eleven seconds later; transfers ran until 21:23 UTC—about 2 hours 52 minutes—with later attempts to edit withdrawal records and two forged BTC orders that failed after 21:22 UTC, per the Cos/CryptoTimes wrap of the interim notes. Mandiant’s parallel note, relayed through Bitget’s X account the same day, says the attacker gained unauthorized access to certain third-party security appliances, moved laterally into the exchange wallet environment, and reached warm and hot wallets—again with no evidence private keys leaked and cold wallets unaffected.
Why the interim notes matter for the Watchlist. Until today, the third-party-product story was largely Bitget’s own September 28 framing beside BTC reopen. SlowMist’s recovered withdrawal tool is the first independent forensic object tying forged instructions to the signing/withdrawal path GoPlus and Chen’s test-transfer interview (9980) already sketched. The August 31 foothold also reframes “incident week” as a multi-week dwell problem for any exchange running the same unnamed security stack—vendors for Product A and Product B remain undisclosed.
Laundering and reopen context stay separate chapters. MistTrack (SlowMist’s on-chain unit) says suspected operators are still routing via automated CoW Protocol orders into Chainflip deposit contracts before Bitcoin CoinJoin; Chainflip has blocked some flows while splitting outpaces AML/KYT, per Cos. That sits beside the THORChain refuse-service tracker (10236 / sibling 9851), not inside tonight’s forensic UPDATE. Retail rails: USDT stage fired this morning (10355); remaining tokens, fiat, and P2P stay aimed at October 2. Bitget says it will publish a fuller security report this week; both firms label today’s notes interim.
What this tick is not. It is not a rehash of 9908’s Bitget-only third-party claim alone, not the USDT reopen meter (10355), and not a final attribution to North Korea—still a working theory from Bitget, Elliptic, and investigators with no government formal call. The unused primary is SlowMist/Mandiant’s September 30 interim clock starting August 31 plus the recovered custom withdrawal tool.
What to watch on-chain next: whether Bitget’s fuller security report this week names Product A/B vendors or freezes more stolen flow; whether MistTrack’s CoW→Chainflip→Bitcoin path keeps outrunning blocks; and whether the October 2 remaining-assets reopen stays clean after the USDT stage.
Bottom line: SlowMist and Mandiant’s interim notes put Bitget’s intrusion on the clock from August 31—a zero-day foothold and custom withdrawal tool weeks before the September 24 drain—so the next forensic beat is whether Bitget’s fuller report this week names the vendors and freezes more of the trail.
Disclaimer: This article is provided for informational and educational purposes only. It does not constitute financial, investment, legal, or trading advice. The NFT market is highly volatile, and past performance is not indicative of future results. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets. The cover image for this article may have been created using artificial intelligence (AI).
