This article is a crypto security special, focusing on two disclosed security incidents. There has been new progress in the investigation into the Bitget hack, with SlowMist tracing the source to a zero-day vulnerability that emerged on August 31. Meanwhile, MetaMask has exited as a Lido validator and is investigating an undisclosed security incident, saying that the wallet is not at direct risk for now. The two incidents involve an exchange and a mainstream wallet gateway, respectively, and are important recent developments in the crypto security sector.
Entities involved include exchange Bitget, security firm SlowMist, wallet provider MetaMask, and Lido validator-related arrangements. The Bitget incident is seen as an important case in exchange security, with known information involving a zero-day vulnerability, security products, and a custom withdrawal tool; known information on the MetaMask incident includes exiting as a Lido validator, investigating an undisclosed security incident, and no direct risk to the wallet for now. This article covers only the security incidents themselves and does not address other industry developments such as market fund flows, regulatory personnel changes, or Layer 2 upgrades.
Bitget Hack Traceback: SlowMist Points to August 31 Zero-Day Vulnerability
According to disclosed information, SlowMist said the source of the Bitget hack points to an August 31 zero-day vulnerability. This statement means the investigation has moved from the previously general hack incident to a more specific time point and vulnerability type. Related information also mentions that the incident involves a zero-day vulnerability, security products, and a custom withdrawal tool, suggesting the scope of the investigation may cover platform security components, withdrawal processes, and related risk control tools. Based on available information, SlowMist's conclusion provides a key clue for tracing the incident, but the full attack path, scope of impact, and follow-up handling are still pending further disclosure. From a timeline perspective, August 31 has become a key node in the investigation. The related information does not say when the vulnerability was discovered, when it was exploited, or when the platform completed remediation. Therefore, if subsequent disclosures can cover the discovery of the vulnerability, the occurrence of the attack, emergency response, and completion of remediation, it will help the industry understand the full picture.
Exchange Security Case: Security Products and Custom Withdrawal Tool in Focus
The Bitget hack is regarded as an important case in exchange security. Its significance lies in the fact that the incident is not a simple single-point risk but simultaneously involves multiple links, including a zero-day vulnerability, security products, and a custom withdrawal tool. For exchange platforms, withdrawal review, deployment of security products, and emergency response form a continuous line of defense. Once a vulnerability is exploited, existing protections may face challenges, and if a withdrawal tool has design or configuration issues, it may also affect the effectiveness of risk blocking. Therefore, key points for follow-up attention should include: how the vulnerability was exploited, which security products were affected, what role the custom withdrawal tool played in the incident, and whether the platform has taken remediation and isolation measures. Related information does not disclose the scale of affected assets, user compensation arrangements, or the attacker's identity, and related conclusions still need to be based on official investigation results. For other exchanges, the reference value of this case is that security products and withdrawal tools are not isolated modules; they need to operate in coordination with vulnerability monitoring, risk control strategies, and emergency mechanisms.
MetaMask Exits Lido Validator: Wallet Security Investigation Underway
On MetaMask's side, related information shows that it has exited as a Lido validator and is investigating an undisclosed security incident, while saying the wallet is not at direct risk for now. MetaMask is a mainstream wallet gateway, and its security investigation involves user asset security and trust, drawing relatively high attention. Available information does not indicate whether there is a direct causal relationship between exiting as a Lido validator and the undisclosed security incident, nor does it disclose incident details, affected parties, or investigation progress. What can be confirmed is that MetaMask uses 'the wallet is not at direct risk for now' as its external statement, which helps distinguish risks to the wallet itself from the broader security investigation. Because MetaMask is a mainstream wallet gateway, its exit as a Lido validator may involve validator operation arrangements, risk isolation, or investigation needs, but related information does not give specific reasons. Therefore, before further official clarification, exiting as a validator should not be directly equated with the consequences of a security incident. Follow-up attention is needed on the investigation results, whether the arrangements after exiting as a Lido validator are adjusted, and whether the related security incident will further affect user asset security.
Common Observations on the Two Incidents
The two incidents involve an exchange and a wallet gateway, respectively, and both fall within the field of crypto infrastructure security. In the Bitget incident, SlowMist provided traceback clues, reflecting the role of third-party security firms in exchange incident investigations; MetaMask emphasized that the wallet is not at direct risk for now, showing that during a security investigation, clearly defining risk boundaries is important for stabilizing user expectations. However, currently disclosed information is limited and insufficient to support classifying the two incidents as the same risk or a systemic risk conclusion, nor should it be used to infer broader systemic risk or simply attribute different incidents to the same cause.
Follow-Up Areas of Attention
In the future, attention can be paid to the complete traceback conclusions of the Bitget hack, including the specific impact of the zero-day vulnerability, the role of security products and the custom withdrawal tool in the attack chain, and the platform's subsequent remediation and risk control adjustments. On MetaMask's side, attention can be paid to the investigation results of the undisclosed security incident, whether the wallet's risk status changes, and follow-up arrangements after exiting as a Lido validator. For the industry, the two incidents suggest that security transparency, emergency response, and information disclosure at infrastructure links such as exchanges, wallets, and validators will continue to affect user trust and the development of industry security standards.
