BLOCKCHAIN AI.NEWS

Security

A Hidden Script Inside Bitget Was Reading a Database Password on August 31

SlowMist's interim report, posted to GitHub overnight, dates the first malicious activity 25 days before the $388 million theft, to a zero-day in a security product it will only call Product A. Its transfer window runs to 21:23 UTC, the same minute this desk found on Ethereum, and 74 minutes past the point where the chief executive's account stops.

Editorial illustration: a tall mirrored glass cabinet stands in an empty hall with a small panel near its base outlined in electric blue and warm gold light leaking from inside; a chrome calendar ring lies on the floor beside it
✓ SlowMist's Investigation Progress Report (English and Chinese, committed Sep 30, 02:47 UTC) read in full by this desk · Earliest reports this desk found: PANews and Bitcoin.com News (Sep 30) · Also Cointelegraph · Gracy Chen's account via The Block (Sep 28) · Ethereum transfers as read on Blockscout in this desk's Sep 29 story

The earliest entry in SlowMist's timeline of the Bitget theft is not a transfer. It is a script. "The earliest malicious activity identified in the available logs dates to August 31," the firm's interim report says. "A service running on one of Product A's nodes was affected by a zero-day vulnerability. The attacker ran a hidden script under the service process, launched a command to read the environment variable containing the database password, and connected to the database."

The money left on September 24. Counted in SlowMist's time zone, which is eight hours ahead of UTC and puts the theft on September 25, that is 25 days between the first sign of the attacker and the first coin out the door. The report does not say what the attacker did with the database once connected, and it does not say the script ran continuously. It says "similar hidden-script activity was observed on two other nodes on September 23 and September 25," and draws the only conclusion the logs support: "the affected service environments had already been compromised before the assets were transferred out."

Two products, no names

SlowMist was "invited by Bitget" on September 25, the report says, and its findings run "as of September 29." The six-page document, posted to the firm's public Knowledge-Base repository at 02:47 UTC on September 30 in English and Chinese, identifies "malicious activity involving two third-party security products and a wallet application host." The products are "referred to as Product A and Product B." That is one step more than Bitget itself has offered. As this desk reported on September 29, the exchange's incident page says the attacker "may have exploited a vulnerability in a third-party security product," singular, and names nothing.

Product A is where the zero-day was. Product B is where the attacker showed up wearing an employee. "In the early hours of September 25, the attacker accessed Product B's management platform using an internal employee's identity," the report says. From 00:07 local time, which is 16:07 UTC on September 24, the attacker "made three consecutive attempts to inject system commands into Product B's task parameters to write malicious files," then "submitted code through the platform's web execution endpoint, attempting to modify server configuration, write a communication relay file, and upload and assemble malicious program files in batches."

How the employee's identity was obtained, whether Product A's database led to Product B, and what either product actually is are questions the report leaves open. "We are continuing to investigate how the attacker moved between the systems involved," it says. Every page carries the notice that the document is "intended solely for the use of the designated recipient(s)," which sits oddly on a file the firm committed to a public repository.

A tool built for one wallet system

The report's second finding is the thing that did the stealing. SlowMist recovered "a highly customized withdrawal tool from files the attacker had deleted." It "was tailored to the wallet system's withdrawal logic. It forged risk-control parameters in its code, constructed withdrawal requests, and invoked the withdrawal process." The host log puts the tool's start at 01:49 local time, 17:49 UTC, 42 minutes before the first coin moved.

That squares with what Bitget chief executive Gracy Chen told The Block on September 28: fraudulent commands went straight to the wallet system, and the trickiest part was that the attacker deleted the traces. SlowMist's contribution is that the deletion did not hold. The tool was recovered, and someone has now read the code that told Bitget's own risk controls what they wanted to hear.

The clock SlowMist keeps

"On-chain verification shows that the earliest transfer verified to date occurred at 02:31:00 on September 25, when the attacker's address received 93 TRX," the report says. "Eleven seconds later, the receiving address on Ethereum received 0.84 ETH. The compiled transfer records extend to 05:23:11 that day, spanning approximately 2 hours and 52 minutes across multiple blockchains."

Two of those numbers differ from the chief executive's. Chen, via The Block, described the test transfers as 0.184 ETH and 193 TRX. SlowMist says 0.84 ETH and 93 TRX. The ETH figure is the one this desk read on Blockscout on September 29, a 0.84 ETH transfer at 18:31:11 UTC from a wallet the explorer labels as Bitget's. The desk has not independently checked the Tron leg.

The end time matters more. Chen's account, as The Block reported it, has 17 large transactions ending at 20:09 UTC. This desk found one more: 223.2 ETH sent to the attacker's Ethereum address at 21:23:11 UTC, from the same wallet that sent the 18:31 test. SlowMist's compiled records end at 05:23:11 local time. That is 21:23:11 UTC, to the second.

September 24, three accounts of the same evening (UTC)

TimeSlowMist's reportBitget and its CEOEthereum, read by the Desk
Aug 31Hidden script on a Product A node reads the database password
Sep 23, 25Similar script activity on two more nodes
16:07Three command-injection attempts on Product B, under an employee's identity
17:49Custom withdrawal tool starts running
18:31:0093 TRX to the attacker193 TRX and 0.184 ETH test transfers
18:31:110.84 ETH to the attacker0.84 ETH from a Bitget-labeled wallet
18:58Large transfers begin34.75M USDT
19:05Reconciliation flags a discrepancy; withdrawals blocked
20:09Last of 17 large transactions1,879.2 and 1,395.9 ETH
21:22 onTwo forged BTC withdrawal orders error out; attacker reads logs and retries
21:23:11Compiled transfer records end223.2 ETH from the 18:31 wallet
21:44Signing services shut down
Sources: SlowMist's Investigation Progress Report (times converted from UTC+8 by the Desk); Bitget's incident page and Gracy Chen's account via The Block, as reported by this desk on Sep 29; direct transfers into the attacker's Ethereum address read on Blockscout by the Desk. Blank cells mean that source does not mention the event.

What happened after the last coin

The attacker did not stop when the transfers did. "After the asset transfers had begun, the attacker also attempted to modify withdrawal records directly in the wallet database and invoke withdrawal tasks on the local host," the report says. "Logs show that two fabricated BTC withdrawal orders entered processing and returned errors. They also record the attacker subsequently reviewing logs, querying order status, and making further attempts. These actions occurred after 05:22."

That is 21:22 UTC, one minute before SlowMist's transfer window closes and 22 minutes before Bitget's timeline says it shut down "wallet withdrawal services, including signing services." The forged orders failed. The report does not say why, and does not say whether the failure was a control working or luck.

The report's disclaimer deserves a reading too. SlowMist's analysis "is based on documents and materials supplied to SlowMist by the information providers," and the firm "assumes that the Provided Information contains no omissions and has not been tampered with, deleted, or concealed." In a case whose central fact is that the attacker deleted files, that is a large assumption to print, and SlowMist prints it.

The Take

Three accounts of one evening now exist, and they agree on almost everything except where the evening ends. Bitget's chief executive stops the clock at 20:09. The chain, and now Bitget's own investigator, run it to 21:23. The gap is 74 minutes during which, on Ethereum alone, a Bitget-labeled wallet sent another 223 ETH, and during which the attacker was in the wallet database forging Bitcoin orders. The signer was still on. Nobody has yet explained why. The August 31 date is the bigger fact for everyone who is not Bitget, because Product A has other customers and 25 days is long enough for a second victim to exist without knowing it. SlowMist's silence on the product's name is presumably Bitget's silence, and Bitget's silence is presumably the vendor's fix schedule. Every day that holds is a day the vendor's other customers are relying on a document that calls itself confidential and was published to the world.

More on the subject