# SlowMist links Bitget theft to security-product exploit and withdrawal tool

_Published Wednesday, September 30, 2026 at 4:21 PM EDT · Security · Latest · Tier 2 — Notable_

![SlowMist links Bitget theft to security-product exploit and withdrawal tool — Primary](https://s3-images.ctmedia.io/media/article-covers/2026/09/01M3RTGB6W8ZNJPV69XHVA5WD7/hi-crypto-mixers-and-crosschain-bridges-how-hackers-hide-stolen-assets.jpg)

SlowMist traced malicious activity linked to Bitget's $388 million theft to Aug. 31, when an attacker exploited a zero-day vulnerability in a third-party security product. Its ongoing investigation identified activity involving two security products and a wallet application host.

The security firm recovered a deleted tool that forged risk-control parameters, constructed withdrawal requests and invoked withdrawals. It is still examining how the attacker moved between systems. Bitget CEO Gracy Chen said the vulnerability exposed high-level internal credentials, while private keys and cold wallets were not compromised.

## Sources

- [Cointelegraph](https://cointelegraph.com/news/bitget-hack-zero-day-slowmist-investigation)

---
Canonical: https://techandbusiness.org/newswire/qeHta8PPNQTTcO2PNjwOQt
Published: 2026-09-30T20:21:10.134Z
Story chronology: 2026-09-30T10:05:39.627Z
Retrieved: 2026-09-30T22:19:30.452Z
Publisher: Tech & Business (techandbusiness.org)
