1.7 million Gate users have been stolen. Has face recognition been hacked?

By Sanqing, Foresight News
On July 8, Gate Exchange user “First Beautiful Girl (@jheioff)” An article was posted on the X platform stating that its Gate exchange account was stolen and about $1.7 million in assets were shorted. Gate's official Chinese-language account later confirmed that the account completed a total of 5 withdrawals on July 7, totaling 49.96 ETH, 746,475 HSK, and 1,565,982 USDT, equivalent to about 1.7 million US dollars.

The user said that the account has enabled mobile verification, Google Authenticator, and email verification, but the phone did not receive any verification code during the entire process, and he himself never provided a video, handheld ID, or login screen recording.
Gate's Chinese-language official later released a full timeline response, listing every step of the account's operations from July 4 to 7, including live face verification, SMS and email verification codes, and fund password changes. The back-office records all showed “Verification Passed.” The incident was initially determined to be an individual case, and there were no systemic security flaws. The evidence chains between the two sides conflicted with each other. The incident sparked extensive discussions in the Chinese crypto community and prompted some users to withdraw money from Gate.
In response to the further development of the incident and some questions and details, Foresight News has sought evidence from both parties. Gate stated that it has actively communicated with the user and is unable to respond until the final investigation of the incident is completed. The other party had no response as of press time.
The more specific the evidence, the sharper the contradiction
According to the first version of the timeline announced by Gate, on July 4, a “new device” initiated a password and security reset request, and the reset was completed after live face verification (that is, real-time detection of face movements to distinguish real people from photos, videos, or forged images), SMS verification codes, and email verification codes; on July 5, the account was untied with a video recording of the 2019 Alipay C2C order; on July 6, the account was untied with the phone; on July 7, the account was verified by Google.” There was a login operation on the Mac web version of the “old device in the past”;
On the same day, the account initiated a withdrawal to a new address. The withdrawal was released after live face verification, Google verification code, and fund password. Afterwards, the new address was added to the unverified whitelist. The account completed a total of 5 withdrawals, totaling about $1.7 million.@jheioffHe immediately denied each one by one, claiming that he had never done the above face verification, had not submitted any videos or screen recordings, and had not applied to unbind his phone or change his email address.
The controversy did not stop at this round of saying their own words.
On the evening of July 8, Gate gave a second round of responses, adding quite specific details: face recognition at 19:44 (UTC+8) on July 4, the corresponding IP was 42.200.39.1XX, the device was iPhone 14. The live test results showed “low risk of inactivity” and was “highly consistent” with the KYC archived face; at around 3 a.m. on July 5, the account party also submitted a video of myself holding a document with a handwritten document for unbinding verification; on the same day, 21 On the recording screen of the 2019 Alipay C2C order submitted at 26 o'clock, Gate stated that it had cross-checked with its own transaction records. The details were multiple payment amounts at “22:28 on October 9, 2019.”
@jheioffThe second round of responses was also tit-for-tat: she made it clear that she was currently using the iPhone 16 Pro. Her previous device was the iPhone 13, and both were not the iPhone 14 in the Gate records; she had already fallen asleep at 3 a.m., and was unable to submit a video of her handheld ID; and she was completely unaware of the 2019 Alipay video.
However, there were also few coincidences in this round of responses. She admits that when she logged in to the Mac website on July 7, it was probably her own browser because she usually used to hang exchange websites such as Gate in her browser. She immediately added that the login did not mean that she changed the email address, unbound the phone, reset the password, and finally made the withdrawal, and asked Gate to explain the private IP of the intranet shown in the log as 10.0.10.9, as well as the device's fingerprint and real public network IP, which had not been disclosed.
In response, Gate said that the operation was handled by the customer service who manually verified the identity, so the log was shown as an intranet IP, and much of the information requested by the victim was confidential information related to the platform's core risk control and could not be directly provided to the outside world.

As to whether Alipay's records can be traced back to 2019, some voices in the community questioned that Alipay did not support retrieving transaction records from five years ago. However, according to the author's actual testing and verification Alipay's official help center, billing records can be permanently queried, and even after deletion, they can still be queried by “issuing a transaction flow certificate”.
As of July 9, Gate gave the closest point to a “real hammer”: the 2019 Alipay recording screen was confirmed to be true after cross-checking, and theoretically, only the real person with the account can log in to Alipay themselves.
Early the next morning, Gate also explained another “account email has been tampered with” rumor circulating in the community (involving another UID): The 涉事账户显示的@mail.bter.com/@mail .gate.io suffix email is a placeholder email automatically generated by the platform for registered users with a pure mobile phone number. It cannot be independently logged in to send and receive emails. It is only used to fill in back-office information, and is not bound by a third party.

Multiple speculations point to the same vulnerability
After the incident unraveled, the community gave several conflicting explanations.
@hebi555It is suggested that attackers may use leaked KYC data and AI face-swapping technology to falsify a face video sufficient to pass live detection;
@ChzhshchAI与@datieziStarting from the intranet IP anomaly, it is suspected that the operation was completed with the cooperation of exchange internal personnel;
@dajingou1According to the long-article analysis, this is more like the result of terminals being implanted into Trojans over a long period of time, and information continues to be stolen.
Another speculation is that the account's real-name KYC information doesn't belong@jheioffI registered myself, but I borrowed someone else's identity. In response to this,
@jheioffThere has been no positive response in public material.
Gate characterized the incident as an “individual case,” but this was the judgment of one party concerned. Currently, no independent third party has intervened to verify it, and the investigation is still led by Gate.
However, vivo testing has been broken, and there have long been precedents in the field of traditional finance. In 2022, the Beijing police reported a case where Bank of Communications depositor funds were stolen: the attackers completed large transfers and password resets through the bank's face biopsy 6 times. The depositor himself had no idea about this. There were at least 6 similar victims, and the amount involved exceeded 2 million yuan; tests by the Tsinghua University RealAI team in 2021 showed that they could break through the face recognition system of 19 Android phones within 15 minutes and successfully bypass some financial apps Testing.
Funds are voting with their feet
On the day the incident was made public,@xiaomustock与@0xfengxunWait for the account's warning posts to spread rapidly, and some users chose to withdraw money from Gate as soon as possible to take refuge;
@forevergalxyOthers questioned the exchange's organization of positive voices on social platforms and evaded core evidence.
According to DeFilLama data, after the incident unraveled, Gate's net outflow over the past 24 hours was approximately US$86.58 million, which is significantly higher than the data of other exchanges for the same period.
For Gate, this is not just a case-by-case dispute, but a public test of crisis disclosure ability. The exchange chose to issue statements in stages and give a timeline for operation in an attempt to hedge against loss of trust with transparency. The longer it takes, the harder it will be to break Rashomon.
Leaving aside the determination of responsibility, this case itself also left a few practical tips for ordinary users: before making large withdrawals, you may want to set a separate delayed payment or manual review for the “whitelist of unverified addresses” rather than default release; turn off cloud sync as much as possible and set a separate strong password for the secondary verification tool; pay more attention to the actual display of the exchange's official verification SMS/email address on a daily basis to avoid ignoring key verification codes as marketing information and setting anti-phishing codes that you can remember; regularly check whether the email address associated with the account is the actual email address you are using, especially Old accounts that are quickly registered with a mobile phone number can easily be overshadowed by a placeholder email automatically generated by the system.
At the same time, it is necessary to avoid revealing the size of specific positions on social platforms or public places. High-profile “posting orders” and “Lufu” itself will become targets of social engineering attacks; in addition, face recognition has been shown to have the possibility of face swapping and falsification, and minimizes the retention and dissemination of clear, multi-angle facial photos and videos on social media and unfamiliar third party channels. Once collected, such materials may be used to train or synthesize face-swapping materials that can trick live detection.
Twitter:https://twitter.com/BitpushNewsCN
Compare the TG exchange group:https://t.me/BitPushCommunity
Compare TG subscriptions:https://t.me/bitpush



