UPDATE: SlowMist forensic report dates Bitget exploit to August 31 with up to $390M lost
CIE News ·
Forensic findings from SlowMist reveal the Bitget breach started on August 31 via a third-party zero-day flaw, raising estimated losses up to $390.06 million while NEAR Intents blocked $50 million.
As previously reported, Bitget suffered an exploit targeting its hot and warm wallet systems. Forensic findings released by SlowMist show the security breach originated on August 31, 2026, through a zero-day vulnerability in third-party software before unauthorized transfers occurred on September 24. SlowMist has revised the estimated total loss to a range between $387.5 million and $390.06 million, while reporting that NEAR Intents successfully prevented $50 million in attempted swaps by the attacker.
According to reports published by blocksec.com and halborn.com, the intrusion compromised off-chain backend infrastructure to generate spoofed transaction requests rather than exposing private keys. Attackers exploited high-level internal credentials to route forged withdrawals through the exchange's standard authorization workflow. Stolen funds spanned multiple networks, including Ethereum, XRP Ledger, TRON (TRX), and Zcash (ZEC), with the perpetrator rapidly swapping stablecoins into Ethereum (ETH) to evade issuer-level freezes.
Bitget previously confirmed that user balances are fully protected by its $464 million User Protection Fund, while cold storage infrastructure remained untouched. Investigations into the incident remain active with participation from Mandiant, SlowMist, and Elliptic, with observers noting transaction patterns resembling North Korean cyber operations.