Bitget Hack — SlowMist and Mandiant Zero-Day Attribution (September 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·22taLk…iKEHSummary
On September 30, 2026, SlowMist and Mandiant published joint forensic findings on the roughly $387.5 million Bitget exchange hack of September 24, 2026, concluding that attackers first gained access via a zero-day vulnerability in a third-party security product on August 31, 2026 — about 25 days before the theft — rather than through a direct private-key compromise. Separately, on-chain investigator ZachXBT identified five alleged Chinese money launderers said to be operating on behalf of suspected North Korean (DPRK) actors, moving stolen funds through a combination of the CoW Protocol and Chainflip cross-chain bridge. This entry covers only the forensic root-cause attribution and laundering-network findings; it does not restate the general Bitget trust assessment covered on the existing Bitget page.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(4 events)
August 2026
Earliest identified malicious activity: attacker allegedly exploits a zero-day vulnerability in a node of third-party security product 'Product A' to gain initial access and read database credentials.
TechFlow / SlowMist report summarySeptember 2026
Attacker allegedly uses a compromised employee identity to access second vendor tool 'Product B,' deploys a web shell and customized withdrawal tool forging risk-control approvals; approximately $388 million is transferred out across seven blockchains within roughly a three-hour window.
Bitcoin.com News / The Hacker NewsSeptember 2026
On-chain investigator ZachXBT publishes findings identifying five alleged Chinese money launderers operating, he says, on behalf of suspected DPRK attackers, and describes chain-hopping through THORChain and mixers including Wasabi Wallet.
CryptoTimesSeptember 2026
SlowMist and Mandiant publish joint forensic findings attributing the root cause of the Bitget hack to a zero-day exploit against a third-party security vendor first activated August 31, and describing the CoW Protocol / Chainflip laundering route used to move stolen funds.
CryptoTimesDecision Log
- hash: 5ikTmau746xf2XmZS4UgfFWxmj6LQEVAHRdGfvoezsZD
This investigation is cryptographically anchored to the Solana blockchain (1 event). 10 of 10 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 9/30/2026, 12:09:09 PM
last updated: 9/30/2026, 6:34:38 PM
avoid.net — verified advice for a post-truth world