# SlowMist

Type: Company

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/slowmist
Canonical HTML page: https://getcyberbrief.com/entity/slowmist

## Timeline

- **2026-09-30**: Bitget discloses breach — Bitget reveals the zero-day breach and shares findings from SlowMist and Mandiant.
- **2026-09-25**: Bitget discloses $351.6M theft — The exchange announced the loss, suspended withdrawals, said the User Protection Fund will cover affected customers, and linked the attack to North Korean hackers based on IP behavior patterns and on-chain analysis. Law enforcement, Mandiant, and SlowMist are investigating.
- **2026-09-25**: Crypto theft executed — Theft transfers occurred between 02:31 and 05:23 UTC+8, spanning nearly three hours across multiple blockchains.
- **2026-09-24**: Unauthorized transfers detected — Bitget security systems flagged multiple unauthorized transfers from a limited number of hot and warm wallets Thursday evening. Attackers accessed the key backend wallet-service system to forge transfer information and trigger the authorization-signing process.
- **2026-09-24**: Privileged access to security appliances — Mandiant reports threat actor gained unauthorized privileged access to third-party security appliances A and B, deployed a web shell on appliance B, and established C2.
- **2026-09-23**: Additional hidden-script activity — Similar hidden-script activity was observed on two other nodes.
- **2026-08-31**: Earliest malicious activity — Logs show a service on one of Product A's nodes was affected by a zero-day vulnerability; attacker ran a hidden script and accessed a database password.

## Recent coverage (2 stories)

### Bitget Lost $387.5M After Zero-Day in Third-Party Security Appliances
2026-10-01 06:08:30 · Sentiment: Strongly negative · Impact: 8/10 · Sources: 2

A zero-day in two third-party security appliances gave attackers privileged access to Bitget's wallet environment. Mandiant and SlowMist traced lateral movement to the production wallet job server, where a custom withdrawal tool moved $387.5 million.
Full story: https://getcyberbrief.com/story/bitget-zero-day-security-appliances-387m

### North Korean Suspects in Bitget's $351.6M Multi-Chain Crypto Heist
2026-09-25 13:42:58 · Sentiment: Strongly negative · Impact: 8/10 · Sources: 2

Bitget's hot and warm wallet compromise shows attackers moved beyond credential theft into backend transaction-signing infrastructure. Multi-chain impact across Ethereum, XRP Ledger, Arbitrum, and others totals $351.6M, with North Korean groups suspected. The $464M User Protection Fund covers losses, but withdrawal suspension signals ongoing containment.
Full story: https://getcyberbrief.com/story/bitget-351m-north-korean-crypto-heist-cyber

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.