Slowmist's investigation into Bitget's $388 million hack found the attackers first breached a third-party security tool on Aug. 31, 25 days before they drained funds on Sept. 24. The report also traces how the stolen money is now moving through CoW Protocol and Chainflip on its way to bitcoin.
A Zero-Day Opened the Door in August
Bitget hired Slowmist on Sept. 25 to investigate the theft from its hot wallets, and the findings trace the earliest breach to Aug. 31, nearly four weeks before any funds moved. A service on one node of a third-party security product, which Slowmist calls "Product A," was hit through a zero-day vulnerability. The attacker ran a hidden script, read an environment variable holding a database password, and connected to the database. The same activity resurfaced on two more nodes on Sept. 23 and Sept. 25, showing the compromised environment predated the theft itself.
The Theft Took Under Three Hours
Once inside, the attacker moved fast. Using an internal employee's identity, they entered the management platform of a second vendor tool at 16:07 UTC and made three straight attempts to inject system commands. A highly customized withdrawal tool then forged risk-control parameters and triggered the withdrawal process, with the first onchain transfer landing at 18:31 UTC. The last transfer came roughly two hours and 52 minutes later. XRP made up the single largest piece at about $153 million. No private keys were taken; instead, the attackers tricked the internal approval system into signing off on transfers that looked legitimate.
Stolen Funds Are Routing Through Chainflip
The money is still moving. Slowmist founder Cos said Mistrack's Trackagent tool caught suspected North Korean hackers combining CoW Protocol and Chainflip to launder the funds. Automated scripts place swap orders on CoW Protocol, a decentralized exchange aggregator, and route the proceeds to a pre-configured Chainflip deposit contract, where they convert into bitcoin. One day earlier, Chainflip brokers had rejected a direct deposit from the same attackers and returned the funds. Other laundering routes have closed too: Near Intents blocked most of a $50 million laundering attempt, letting $166,000 through and freezing $503,000.
Withdrawals Are Coming Back in Stages
Bitget says its User Protection Fund, holding more than $464 million, covers the loss, with withdrawals returning bitcoin first, then ether, USDT and other assets. Slowmist has not named the vendors behind "Product A" or "Product B" and is still working out how the attacker moved between systems. North Korea-linked groups stole a record $2 billion in 2025, giving any exchange running similar security tools reason to check its own logs back to the end of August.
Source: Bitcoin News
Trading involves risk.