Skip to main content
AVOID.NET

Bitget Hack — SlowMist and Mandiant Zero-Day Attribution (September 2026)

avoid.net/bitget-hack-slowmist-and-mandiant-zero-day-attribution-september-2026→5/100·75% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·22taLk…iKEH

Summary

On September 30, 2026, SlowMist and Mandiant published joint forensic findings on the roughly $387.5 million Bitget exchange hack of September 24, 2026, concluding that attackers first gained access via a zero-day vulnerability in a third-party security product on August 31, 2026 — about 25 days before the theft — rather than through a direct private-key compromise. Separately, on-chain investigator ZachXBT identified five alleged Chinese money launderers said to be operating on behalf of suspected North Korean (DPRK) actors, moving stolen funds through a combination of the CoW Protocol and Chainflip cross-chain bridge. This entry covers only the forensic root-cause attribution and laundering-network findings; it does not restate the general Bitget trust assessment covered on the existing Bitget page.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Bitget Hack — SlowMist and Mandiant Zero-Day Attribution (September 2026)?

Timeline(4 events)

August 2026

Earliest identified malicious activity: attacker allegedly exploits a zero-day vulnerability in a node of third-party security product 'Product A' to gain initial access and read database credentials.

TechFlow / SlowMist report summary

September 2026

Attacker allegedly uses a compromised employee identity to access second vendor tool 'Product B,' deploys a web shell and customized withdrawal tool forging risk-control approvals; approximately $388 million is transferred out across seven blockchains within roughly a three-hour window.

Bitcoin.com News / The Hacker News

September 2026

On-chain investigator ZachXBT publishes findings identifying five alleged Chinese money launderers operating, he says, on behalf of suspected DPRK attackers, and describes chain-hopping through THORChain and mixers including Wasabi Wallet.

CryptoTimes

September 2026

SlowMist and Mandiant publish joint forensic findings attributing the root cause of the Bitget hack to a zero-day exploit against a third-party security vendor first activated August 31, and describing the CoW Protocol / Chainflip laundering route used to move stolen funds.

CryptoTimes
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 10 of 10 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 9/30/2026, 12:09:09 PM

last updated: 9/30/2026, 6:34:38 PM

avoid.net — verified advice for a post-truth world