Skip to content

company

SlowMist

SlowMist is a blockchain security firm offering smart contract audits, threat intelligence, and incident analysis for crypto exchanges and DeFi projects.

Known aliases

  • SlowMist security team

Relationships

No evidence-backed relationships are recorded.

Current stories

invest3 publishers

Issuers and protocols have frozen about 0.2% of the $387 million taken from Bitget

Chainalysis tied the $387 million Bitget hack to North Korea-linked hackers, saying it pushed their 2026 crypto theft past $1 billion. Its AI cut more than 20 hours of tracing to minutes, while the bill falls on a Bitget user fund the exchange puts above $464 million.

Perspective Coverage

3 publishers
Builder
Builder 32%
Operator
Operator 41%
Investor
Investor 27%

Reality

Evidence70
Adoption25
Hype gap+35
Incentives60
Confidence65
invest3 publishers

Attacker drains up to $310K from two Safes through a leverage module the owners switched on

Two Safe multisigs lost up to $310K after an attacker impersonated a Safe to get past FlashLoopAdapter, an Aave leverage add-on the owners had enabled. Aave and Safe's core code held, so the loss fell on owners who let a module move funds without signatures.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 37%
Investor
Investor 25%

Reality

Evidence70
Adoption
Insufficient
Hype gap+12
Incentives35
Confidence72
invest3 publishers

Scammers used GIWA's reserved chain ID to drain 766 ETH before its mainnet launched

Scammers ran a working copy of Dunamu's unlaunched GIWA network on its reserved chain ID 9134 and drained 766.25 ETH from users. The ID got through an exchange's listing checks, so a matching network ID is now weak evidence that a chain is the real one.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 40%
Investor
Investor 22%

Reality

Evidence68
Adoption
Insufficient
Hype gap+12
Incentives60
Confidence70
invest4 publishers

Bitget's CEO doubts the $387.5 million lost through a vendor-linked backend will come back

Bitget CEO Gracy Chen doubts much of the $387.5 million stolen via a backend tied to a third-party security vendor will come back. So far about 0.2% of the loss has been frozen, so the exchange itself is paying for an outsourced security flaw.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 41%
Investor
Investor 34%

Reality

Evidence68
Adoption
Insufficient
Hype gap+5
Incentives55
Confidence70
invest2 publishers

Bitget customers withdrew $463 million in 24 hours, more than the $388 million hack took

Bitget customers pulled about $463 million in the first 24 hours after withdrawals reopened, more than the $388 million hackers stole on September 24. The protection fund covers the theft with about $76 million to spare, so the withdrawals now test whether the $5.7 billion left in reserves matches what Bitget owes customers.

Reality

Evidence60
Adoption
Insufficient
Hype gap+12
Incentives58
Confidence58
security10 publishers

Suspected North Korean attackers used Bitget's own signing process to move $351.6M

Bitget says suspected North Korean attackers took $351.6 million from its hot and warm wallets by spoofing the transaction data that triggers its signing process. Its $464 million user protection fund, held in bitcoin, covers the loss.

Perspective Coverage

10 publishers
Builder
Builder 27%
Operator
Operator 42%
Investor
Investor 31%

Reality

Evidence55
Adoption
Insufficient
Hype gap+25
Incentives70
Confidence60
invest3 publishers

Bitget presses THORChain to cut off the wallets holding its stolen $387.5 million

Bitget CEO Gracy Chen publicly asked THORChain to refuse service to the wallets that took $387.5 million, after Circle and Tether stopped nearly $318,000. Much of the rest now depends on a no-KYC swap protocol that has declined to block stolen funds in earlier hacks, including its own.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 40%
Investor
Investor 22%

Reality

Evidence57
Adoption44
Hype gap+12
Incentives68
Confidence55
invest15 publishers

Most of Bitget's $387.5 million hack loss sits untouched in attacker wallets

Bitget now puts its September breach at $387.5 million, and AMLBot estimates $343 million of it sat untouched in 13 attacker wallets on Sept. 25. The phased withdrawals due from Sept. 28 are the better guide to whether customer money is safe.

Perspective Coverage

15 publishers
Builder
Builder 25%
Operator
Operator 43%
Investor
Investor 32%

Reality

Evidence66
Adoption
Insufficient
Hype gap+20
Incentives60
Confidence62
product3 publishers

Bitget's own approval process moved out $388 million on spoofed transaction data

Bitget says attackers took over a wallet backend system and fed its authorization process spoofed data, moving out $387.5 million without stolen keys. For teams running payouts, the data an approver trusts now belongs on the same review list as the keys.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 40%
Investor
Investor 37%

Reality

Evidence58
Adoption
Insufficient
Hype gap+18
Incentives62
Confidence60

Earlier coverage

  1. The attacker's self-set 15% leaves Liquid's peg wallet about 600 BTC short

    Invest · September 11, 2026 · 1 publisher

  2. The fake Qwen repo undershot its advertised weights by a factor of 34,000

    Invest · August 28, 2026 · 1 publisher

  3. A 2022 oracle hack starts moving again, three days after Pando shut its books

    Invest · August 18, 2026 · 1 publisher

  4. A Connecticut judge just priced prompt injection: no fine, no e-filing

    Invest · August 16, 2026 · 2 publishers