Doctorcrypto About RSS Subscribe
Doctorcrypto
Home › Opinion › SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit
Opinion

SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit

By Priya Chen · · 2 min read

Blockchain security firm SlowMist has traced the origins of a recent Bitget hack to malicious activity that began as early as Aug. 31, pointing to a sophisticated zero-day exploit that went undetected for weeks before funds were stolen.

Weeks of Hidden Activity

According to SlowMist's investigation, the attackers did not strike immediately. Instead, evidence of malicious behavior surfaced weeks ahead of the actual theft, suggesting the perpetrators had established a foothold within the targeted systems well in advance.

The security firm's analysis indicates the breach relied on a zero-day vulnerability — a previously unknown flaw that developers had no time to patch before it was exploited. Such vulnerabilities are among the most dangerous in cybersecurity because they leave defenders with no warning and no ready fix.

A zero-day exploit gave attackers a silent window to operate long before anyone noticed the danger.

The Tools Behind the Breach

Investigators say the attack involved multiple components working in concert. SlowMist identified two security products and a custom-built withdrawal tool that appear to have played roles in enabling the unauthorized movement of funds.

The use of a bespoke withdrawal tool points to a high level of premeditation, with the attackers tailoring their methods specifically to the environment they were targeting rather than relying on off-the-shelf malware.

Key elements flagged in the investigation include:

  • A zero-day vulnerability exploited before detection
  • Two security products implicated in the incident
  • A custom withdrawal tool built for the attack

What It Means for Exchanges

The findings underscore the persistent threat facing centralized crypto platforms, where attackers increasingly combine advanced technical exploits with patient, long-term planning. The lengthy gap between the initial intrusion and the eventual theft highlights the difficulty of detecting stealthy adversaries operating inside trusted systems.

For the broader industry, the incident serves as a reminder that robust monitoring, rapid vulnerability response and independent security audits remain critical defenses. As threat actors grow more methodical, exchanges face mounting pressure to identify anomalies early rather than discovering breaches only after funds have vanished.

Was this useful?👍 Yes👎 No
↑