Attackers infiltrated Bitget's systems on Aug. 31, nearly four weeks before draining $388 million from the exchange's hot wallets on Sept. 24. A Slowmist investigation released today reveals the extended dwell time and the breach mechanics.
The blockchain security firm, brought in by Bitget on Sept. 25, identified the earliest malicious activity in available logs on Aug. 31. A service on one node of a third-party security product was compromised through a zero-day vulnerability. The attacker exploited the flaw to run a hidden script, extract an environment variable containing a database password, and connect to the database.
The same hidden-script activity appeared on two additional nodes on Sept. 23 and Sept. 25, confirming the affected service environments were compromised before any assets moved. This aligns with Bitget's earlier explanation that attackers exploited a third-party security product to acquire high-level internal credentials.
The actual drain started Sept. 24. Arkham Intelligence tracked $228 million leaving Bitget in 18 minutes, distributed across seven blockchain networks. XRP accounted for the largest haul at approximately $153 million.
The attackers never touched private keys. Instead, they manipulated Bitget's internal approval system to authorize transfers that appeared legitimate. After the drain began, the intruder attempted to rewrite withdrawal records in the wallet database. Two fabricated Bitcoin withdrawal orders generated errors, and logs show the attacker repeatedly checked order status and retried, indicating an attempt to cover tracks or enable further unauthorized transfers.
The stolen funds are still moving. Slowmist founder Cos said the hackers are using CoW Protocol and Chainflip to launder the assets. Automated scripts place swap orders on CoW Protocol, a decentralized exchange aggregator, and direct the recipient to a pre-configured Chainflip deposit contract. Once a CoW Protocol order settles, assets automatically roll into a cross-chain swap, emerging as bitcoin. This creates rapid obfuscation of fund origins.
Chainflip rejected a direct deposit from these attackers just one day before the successful laundering attempts, returning the funds. Cos warned that Chainflip's anti-money laundering and know-your-transaction checks cannot keep pace with the hackers' sophisticated system.
The hackers constantly split funds across multiple bridges, swap them into bitcoin, employ mixing services, and pivot strategy the moment a laundering route closes. Near Intents blocked the majority of a $50 million laundering attempt, freezing $503,000 while allowing only $166,000 through. Other fund flows connected to the hack have moved through Thorchain, Uniswap, 1inch Fusion, and Stargate protocols.
