Gate Owner Stole $1.7 Million: Who's Lying?

sourceBitpushNews·Wendy·02:48 编辑
Gate Owner Stole $1.7 Million: Who's Lying?

The hottest topic of discussion in the crypto community over the past few days is the “theft case” of Gate users worth 1.7 million dollars.

On July 8, an X ID user called “The First Beautiful Girl” (@jheioff)TweetSaid that the money in my Gate account was gone — 49.96 ETH, more than 740,000 HSK, more than 1.56 million USDT, which added up to about 1.7 million US dollars. However, TA said that he hadn't received any verification codes from beginning to end, nor had face recognition, so the money just disappeared.

Gate.io officially confirmed that the withdrawal actually occurred, but the statement given was completely different: the platform said that all operations had been fully verified, including face recognition, email verification codes, and fund passwords, and not a single step away.

Both sides have each handed out a bunch of evidence, and both seem to have their share of it. There is no third party's conclusion on this matter until now, but all kinds of doubts and speculations have exploded.

timelines

Let's take a quick look at the parties' respective timelines, and you'll find that the strangest part of this incident is — the stories told by both sides are very detailed, but there's just something wrong.

Gate officially issued a detailed explanation on July 8, sorting out the entire process according to the timeline:

On July 4, a new device initiated a request to reset the phone and email address. Gate requires live face verification, SMS verification code, and original email verification code. The reset was completed after all were passed.

On July 5, the account party requested that the phone be untied. The customer service once again confirmed the face activity experience, and also requested the other party to provide a recording of the 2019 historical transaction (Alipay payment record) before unbinding.

On July 6, the Google Authenticator was reset, and the login password and fund password were also changed—the email verification code and original fund password were verified at every step.

On July 7, an old historical device (Mac web) logged in with the old passkey and then initiated a withdrawal to a new address. Gate asked again for a live face, Google verification code, and financial password, all of which passed. This address was then set as a “free verification address”, and 5 withdrawals were completed.

On July 8, users only contacted customer service for the first time and said “funds have been lost”.

image.png

Gate's conclusion is that this is not a system bug or platform security issue. All operations are traceable, are individual cases, and may be related to the user's own information disclosure.

The victim's version is completely different:

TA said that he did not actively reset or withdraw any security items from beginning to end.

Gate claimed that the user used an iPhone to complete live face verification, but TA directly threw out a video of the home surveillance — in the picture, @jheioff was playing in the living room while holding the child, and hadn't touched the phone at all, let alone do any face recognition. @jheioff emphasized that this video can be submitted to the police and the judiciary for verification.

image.png

Users claim that they don't have an iPhone 14 at all (the device mentioned in Gate records), and they haven't received any relevant notification emails or abnormal verification code alerts. Everything is fine with accounts on other exchanges; only Gate has problems.

With the second round of clashes between the two sides, more details were shaken out, but it made things even more confusing.

Gate further revealed that the IP for face recognition on July 4 was 42.200.39.1XX, and the device was an iPhone 14. The live test results were “low risk of inactivity” and “highly consistent” with the face on the KYC file. At around 3 a.m. on July 5, the account side also submitted a video showing the documents and handwritten documents for unbinding verification. At 9:26 p.m. on the same day, the 2019 Alipay recording was also submitted. Gate said that it had cross-checked with his transaction records and was accurate to the payment amount “22:28 on October 9, 2019.”

The victims denied all of this: they used an iPhone 16 Pro, the old device was an iPhone 13, and there was no iPhone 14 at all; they went to bed at 3 a.m., and couldn't submit any videos; they didn't know the 2019 Alipay recording screen at all.

However, TA acknowledged one detail — the Mac web login on July 7 is probably actually my own browser, because I am used to keeping the exchange page permanently in the browser. However, TA emphasized that the login was performed by the person himself, which does not mean that the latter operations were also performed by himself.

What is the most likely cause?

Right now, the community is most focused on three possibilities.

The first is that AI face-swapping has bypassed face recognition. This isn't a sci-fi plot anymore. Deepfake technology in 2026 is already very mature. As long as you have the other party's KYC photo or even a public video, you can generate a fake video that can pass a live test. Gate himself admits that face verification is an “automatic model review” and there is no manual review. If the attackers had the victim's full set of identity data, it was entirely possible to do so. OKX has had a similar case of AI face-swapping for coins before.

The second possibility is that the victim's computer or phone has been implanted into a Trojan horse, and the information has been stolen over a long period of time. Attackers may have obtained browser cookies, email permissions, or even Alipay access through phishing emails or malware. Gate also mentioned in a follow-up investigation that the 2019 Alipay screen recording “can only be recorded by the customer himself or someone who can access the customer's Alipay account” — so they determined that “customer information was seriously leaked or the device was controlled.”

image.png

The third guess is a bit sensitive — internal staff cooperation. Some community members noticed that a “10.0.10.9” intranet IP appeared in the Gate backend, and suspected it was caused by an insider. Gate explained that it was a record left for operations in the era of manual identity verification by customer service, but some people countered, does this not indicate that there is room for use in the manual review process? Anonymous also revealed that “this is not the first time”, suspecting that the KYC data leak is related to insiders. However, in a subsequent statement, Gate clearly denied the internal information leak.

None of these three possibilities can currently be confirmed, but none can be ruled out.

Back to the more fundamental question: Whose words are more credible?

image.png

In terms of evidence, Gate holds a complete technical log — device fingerprints, IP addresses, time stamps, and records that each step of the verification passed. These data exist objectively; in theory, it is difficult to falsify them. But the problem is that these records only prove that “someone” has completed these operations; they cannot prove that that person is the owner of the account.

The surveillance video in the hands of the victim, if real and time-stamped, is really persuasive. But the video itself can also be questioned: can the timestamp be changed? Have you edited the footage?

image.png

Gate also has a point that many people think “makes sense” — Alipay screen recording in 2019. Anyone who has tested it knows that although Alipay bills can be deleted, the entire history can still be checked through the “Issuing Transaction Statement” function. Gate said that such records “theoretically can only be obtained by the real account person logging in to Alipay”. If this judgment holds true, it means that the attackers either hacked TA's Alipay or TA himself participated to some extent — regardless of the circumstances, the “complete ignorance” claim will be challenged.

A warning for ordinary people

Regardless of the final truth of this incident, there are a few lessons that are real and worth referring to for everyone who owns crypto assets.

First, asset diversification is the foundation. Do not keep large amounts of money on exchanges for a long time. Priority is given to using hardware wallets (Ledger, Trezor, etc.) for self-hosting, or using multi-signature wallets. The exchange only keeps the small amount of money needed for daily transactions and transfers out profits regularly.

Second, terminal security must be taken to the extreme. It's best to use a dedicated device to manage large assets; don't mix it up with daily dramas or software; be wary of any message that makes you click a link, download an app, or provide a verification code, regardless of whether the other party claims to be customer service or a friend; don't keep sensitive data, such as screenshots or screen recordings of transactions, in the cloud for a long time or in a location that can be easily accessed.

At the account level, enable all available 2FA, giving priority to hardware keys rather than just SMS or email. Set a whitelist for withdrawals and delays to take effect (if supported by the platform), check login logs and device lists regularly, and freeze immediately if any abnormalities are found. Historical transaction records and KYC data should not be kept in a place where they can be easily leaked for a long time.

More importantly, cultivate safe habits. Don't reveal the size of your assets on public platforms; be wary of any “customer service” or abnormal notifications requiring you to reset security items; if you find a problem, immediately call the police + contact the platform's official + attorney to keep all original evidence (timestamps, chat records, video files).

Finally, when choosing a platform, look more at real community feedback and security history rather than simply on transaction volume. Pay attention to whether the platform regularly discloses proof of reserves (PoR) and whether risk control is strict enough.

The $1.7 million dispute is still a rashomon.

Regardless of the outcome, it reminds us once again: in the age of rapid AI evolution, there is no absolutely secure platform, only a stronger sense of self-protection. Safeguarding your private keys, devices, and privacy is the most reliable way to protect your wealth.

At the time of publication of this article, the incident was still fermenting. It is recommended to continue to pay attention to official updates and view every incident rationally.

Author: Seed.eth


Twitter:https://twitter.com/BitpushNewsCN

Compare the TG exchange group:https://t.me/BitPushCommunity

Compare TG subscriptions:https://t.me/bitpush

Original Link
#AI#Gate#交易所#原创#安全#黑客
说明: All Bitpush articles reflect the author's views only and do not constitute investment advice.

Related

Loading...