According to CNBC, investigation reports published September 30 by Mandiant, part of Google $GOOGL Cloud, and blockchain security firm SlowMist concluded that attackers had compromised two third-party security products in order to reach Bitget's production wallet systems. SlowMist's review of available logs placed the first signs of hostile activity on August 31, tied to the exploitation of a zero-day flaw in one of those products. From there, Mandiant reported, the attackers escalated to privileged system access and circumvented standard withdrawal controls, all without ever extracting private keys. Neither report identified the affected security products or attributed the attack to a specific group.