SlowMist traced malicious activity linked to Bitget's $388 million theft to an August 31 zero-day exploit affecting a third-party security product. Attackers stole the funds from Bitget hot wallets on September 24 UTC before accessing a second security management platform on September 25 using an em