I looked closely at Gate’s official timeline, and the more I read, the more it looks like a "slow-knife" social engineering attack, rather than the platform being breached.
Revisiting a few key points:
· 7/4 A new device initiated a reset of the phone + email; verification passed
· 7/5 Unbound the phone; face + historical transaction records were re-verified a second time
· 7/6 Reset the Google Authenticator and password; the whole process was checked
· 7/7 The attacker logged in using "old device + old password" and withdrew in batches to a new address
· 7/8 Only then did the user notice the abnormality and report it to customer service
Gate says its preliminary assessment is that this is an isolated case, with no evidence of a system vulnerability. It may be related to user information leakage, pending further investigation and details.
My observations are threefold:
1. From the re-linking to the withdrawals, there was a three-day gap—most likely the attacker had complete identity information (documents, historical orders, even face materials), allowing them to bypass risk controls all the way;
2. "Old device + old password" could directly place orders and initiate withdrawals, suggesting that while device fingerprinting and address whitelisting mechanisms work, there is still room for optimization in extreme scenarios;
3. What ordinary users can do is actually quite simple—withdrawal address whitelisting + time-lock/lock-up, a separate email account, switch off SMS 2FA and use a hardware key instead, and don’t leave the front/back of your ID card and selfies in chat logs.
No matter how the final assessment is made, this incident is a reminder: for CEX security, half of the boundary is on the platform, and half is in your own hands.
#Gate #交易所安全 #Self-custody