Security firm SlowMist says the first logged malicious activity tied to the $388 million theft from Bitget dates back to Aug. 31. That was weeks before the funds were taken. The report was published on Sep 30, 2026.
According to SlowMist, on Aug. 31 an attacker used a zero-day vulnerability in a security product made by a third party. The firm's findings also mention a second security product and a withdrawal tool built for the attack.
The stolen funds came from Bitget's hot wallets in September. The source text cuts off before giving the exact date of the theft. It does not name the security products or explain how the withdrawal tool was used.
For anyone already holding a perpetual position on Bitget, the report changes nothing directly. It covers when and how the attack began. It says nothing about funding rates, trading fees or liquidity on Bitget or on Bybit, MEXC or OKX, so this page cannot say whether any of those changed.
Source: cointelegraph — SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit