Bitget opened USDT withdrawals on September 30
SlowMist says the attacker was already inside on August 31, about a month before the theft
a zero-day in a third-party security product, the database password read straight out of it
the tool that drained the wallets forged risk-control parameters, built the withdrawal requests and ran them
so the part built to say "no" was the part that got faked
🔸 USDT: Ethereum, BSC, Solana, Tron
🔸 other tokens, fiat, P2P: October 2, 08:00 UTC
the CEO herself says freezing isn't recovery. she's not optimistic, neither am I
last week I promised a report on my own balance there. it still hasn't left the exchange, and the next update on it lands here, so follow if you're in the same line
#Bitget #HackUpdate #BitgetHotWalletBreachTiedToThirdPartySecurityFlaw