Bitget probes breach with Mandiant and SlowMist

Cryptocurrency exchange Bitget has published independent findings from Mandiant and SlowMist into its September 24 security breach, with both investigations tracing the intrusion to compromised third-party security products that enabled unauthorised access to the exchange’s wallet environment.

The disclosure sharpens the explanation of an incident initially valued at about $351.6 million and later revised to approximately $387.5 million after additional on-chain tracing identified affected transactions involving Zcash and TRON. Bitget has said the higher figure reflected fuller accounting of transfers during the original attack rather than fresh unauthorised movements.

Mandiant, part of Google Cloud, and blockchain security company SlowMist conducted separate investigations. Bitget said their findings broadly matched the attack path it had previously disclosed and provided further detail on how attackers reached its wallet infrastructure.

According to Bitget’s updated account, the attacker may have exploited a vulnerability in a third-party security product to obtain high-level internal credentials. Those credentials appear to have been used to send fraudulent withdrawal commands to the wallet system, causing abnormal transfers that bypassed existing controls. The company said the affected systems were isolated and the underlying vulnerability was remediated.

The first unauthorised transfers occurred at about 18:31 UTC on September 24 from portions of Bitget’s hot and warm wallet infrastructure. Its reconciliation system detected a significant discrepancy at 19:05 UTC, after which risk controls blocked withdrawals across the platform. Bitget activated its highest-level emergency response minutes later and began containment measures.

The exchange said private keys were not compromised and its cold-wallet tier, which holds the largest share of platform assets, remained unaffected. Bitget Wallet, its separate self-custodial product, was also unaffected because it operates on different infrastructure.

Affected assets identified by Bitget include XRP, ether, USDT, Zcash, USDC, USDT0, Tether Gold, BNB, Avalanche and TRON. The transfers occurred across Ethereum and other EVM networks, the XRP Ledger, Zcash and TRON.

Bitget said it had identified the root cause by September 25, revoked and reissued internal login credentials, restructured access to highly sensitive systems and introduced multiple approvals for critical operations. It also notified the relevant third-party vendor and disabled the affected functionality while strengthening withdrawal verification and anomaly monitoring.

The exchange suspended withdrawals after detecting the breach while deposits and trading continued. It subsequently began restoring withdrawals in phases, starting with Bitcoin on September 28 and ether on September 29. USDT withdrawals across selected networks followed, with other supported tokens, fiat withdrawals and peer-to-peer services scheduled for restoration by October 2 after security checks.

Bitget has maintained that customer account balances were unaffected and that losses from the platform-level incident would be covered by its User Protection Fund. At the time of the initial disclosure, the fund held 5,500 bitcoin, which the exchange valued at about $464 million.

Fund tracing and recovery efforts remain under way. Bitget has published attacker-controlled addresses and launched a recovery bounty programme intended to encourage information leading to the freezing or return of stolen assets. It has also said law-enforcement agencies and financial intelligence units were notified as part of the response.

The company has avoided making a definitive public attribution in its formal incident update. Chief executive Gracy Chen had earlier said indicators showed similarities to methods associated with North Korean-linked attackers, but Bitget’s updated explanatory material says attacker attribution should not be treated as confirmed without verified investigative findings.

The breach adds to scrutiny of third-party security technology inside cryptocurrency infrastructure because the forensic findings point beyond a simple theft of private keys. The identified route instead involved trusted security products and internal access, allowing fraudulent instructions to reach wallet systems before the exchange’s reconciliation controls detected the discrepancy.

Bitget said the independent findings would be used to strengthen its security controls. Its post-incident work includes tighter assessments of third-party security products, changes to privileged access and additional monitoring designed to identify anomalous activity earlier.

Arabian Post – Crypto News Network



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…