SlowMist says it has traced key parts of the compromise behind Bitget’s reported $388 million hot-wallet theft, including how attackers moved through multiple components tied to third-party security products and used a custom withdrawal tool to extract funds. In a progress update published with an incident-response report, SlowMist links the earliest observed malicious activity to Aug. 31, when an attacker allegedly exploited a zero-day flaw in a third-party security product. The firm later identified additional suspicious actions across other affected nodes and described attempts to execute fraudulent withdrawals across several blockchains. Key takeaways SlowMist points to an Aug. 31 zero-day exploit in a third-party security product as the start of the logged intrusion chain. According to SlowMist’s findings, attackers used a hidden script to access a “Product A” database using a password pulled from an environment variable. A custom tool was used to manipulate Bitget’s withdra...