Gatecoin Hack: Difference between revisions
(Integrating information from Twitter and Palantine King post. Reviewing to add more sources in.) |
(30 minutes. Integrated infromation from Reddit thread. Gatecoin homepage information integrated better into the about section. Reviewed Twitter and added information on May 20th tweet/Reddit update.) |
||
| Line 3: | Line 3: | ||
Gatecoin was one of the first regulated digital asset exchanges. This didn’t stop the hack of 185,000 ETH and 250 BTC. According to a forensic analysis, the exchange may have been the victim of a man-in-the-middle attack. The malicious external party involved in this breach managed to alter their system so that BTC and ETH deposit transfers bypassed the multisig cold storage and went directly to the hacker’s wallet during the breach period. The company fired their CTO, managed to raise $500k in order to reopen, and ultimately repaid all customers. They were saved by maintaining large cold wallet reserves which appear to have been properly stored, and appear to have dealt with the issue transparently. Having hot wallet insurance would have further assisted with the recovery. A system like Proof of Reserves or an automated alert system could have allowed the issue to be noted sooner. | Gatecoin was one of the first regulated digital asset exchanges. This didn’t stop the hack of 185,000 ETH and 250 BTC. According to a forensic analysis, the exchange may have been the victim of a man-in-the-middle attack. The malicious external party involved in this breach managed to alter their system so that BTC and ETH deposit transfers bypassed the multisig cold storage and went directly to the hacker’s wallet during the breach period. The company fired their CTO, managed to raise $500k in order to reopen, and ultimately repaid all customers. They were saved by maintaining large cold wallet reserves which appear to have been properly stored, and appear to have dealt with the issue transparently. Having hot wallet insurance would have further assisted with the recovery. A system like Proof of Reserves or an automated alert system could have allowed the issue to be noted sooner. | ||
This exchange or platform is based in Hong Kong, or the incident targeted people primarily in Hong Kong. | This exchange or platform is based in Hong Kong, or the incident targeted people primarily in Hong Kong.<ref>https://twitter.com/search?q=(from%3AGatecoin)%20until%3A2016-06-01%20since%3A2016-05-06&src=typed_query</ref> | ||
== About Gatecoin == | == About Gatecoin == | ||
Founded and established in 2013 in Hong Kong, Gatecoin primarily focused on Bitcoin and Ethereum markets<ref name="thenextweb-16" />. In 2015, Gatecoin | Founded and established in 2013 in Hong Kong, Gatecoin primarily focused on Bitcoin and Ethereum markets<ref name="thenextweb-16" />. Gatecoin was a regulated and secure financial institution specializing in blockchain assets<ref name=":10">[https://web.archive.org/web/20160505123951/https://gatecoin.com/ Gatecoin Homepage Archive May 5th, 2016 6:39:51 AM MDT] (Accessed Apr 18, 2024)</ref>. Gatecoin emphasized compliance and transparency, boasting KYC and AML processes supported by a major compliance solutions provider<ref name=":10" />. In 2015, Gatecoin launched a new Bitcoin exchange which featured robust security measures<ref name=":12">[https://cointelegraph.com/news/gatecoin-launches-bitcoin-exchange-with-segregated-bank-accounts Gatecoin Launches Bitcoin Exchange with ‘Segregated Bank Accounts’ - CoinTelegraph]</ref>. These measures include segregated client bank accounts, multi-signature cold storage, and continuous monitoring by an external IT security firm<ref name=":12">[https://cointelegraph.com/news/gatecoin-launches-bitcoin-exchange-with-segregated-bank-accounts Gatecoin Launches Bitcoin Exchange with ‘Segregated Bank Accounts’ - CoinTelegraph]</ref>. The company emphasizes its commitment to regulatory compliance, operating under a Hong Kong Money Service Operator license and adhering to AML/KYC rules<ref name=":12">[https://cointelegraph.com/news/gatecoin-launches-bitcoin-exchange-with-segregated-bank-accounts Gatecoin Launches Bitcoin Exchange with ‘Segregated Bank Accounts’ - CoinTelegraph]</ref>. Gatecoin's segregated bank accounts ensure that clients' funds are kept separate from operational expenses, minimizing counterparty risks<ref name=":12">[https://cointelegraph.com/news/gatecoin-launches-bitcoin-exchange-with-segregated-bank-accounts Gatecoin Launches Bitcoin Exchange with ‘Segregated Bank Accounts’ - CoinTelegraph]</ref>. | ||
The exchange allows users to trade Bitcoin against USD, Euro, and HKD, with plans to integrate Ripple into its platform soon<ref name=":12">[https://cointelegraph.com/news/gatecoin-launches-bitcoin-exchange-with-segregated-bank-accounts Gatecoin Launches Bitcoin Exchange with ‘Segregated Bank Accounts’ - CoinTelegraph]</ref>. | The platform promises deep liquidity through a market maker rebate program and features an instant buy/sell option for seamless currency swaps<ref name=":10" />. The exchange allows users to trade Bitcoin against USD, Euro, and HKD, with plans to integrate Ripple into its platform soon<ref name=":12">[https://cointelegraph.com/news/gatecoin-launches-bitcoin-exchange-with-segregated-bank-accounts Gatecoin Launches Bitcoin Exchange with ‘Segregated Bank Accounts’ - CoinTelegraph]</ref>. Users can easily buy and sell bitcoin, ether (Ethereum), and DAO tokens worldwide with various fiat currencies, benefiting from public live-data streaming, a fully documented REST API, and dedicated customer support<ref name=":10" />. The exchange's trading system is decentralized, modular, scalable, and highly secured, employing bank-grade security procedures and segregated client accounts<ref name=":10" />. Moreover, Gatecoin offers a smart and mobile-optimized interface for intuitive trading experiences, continually enhancing its platform for user convenience and efficiency<ref name=":10" />. | ||
Aurélien Menant was the CEO of Gatecoin through 2015 and 2016<ref name=":0">[https://old.reddit.com/r/gatecoin/comments/4jb1la/official_statement_regarding_gatecoin_hot_wallet/ OFFICIAL STATEMENT REGARDING GATECOIN HOT WALLET BREACH - Reddit] (Accessed Apr 2, 2024)</ref>. Looking ahead from 2015, Gatecoin expressed aims to expand its business to the US and Europe, focusing on obtaining the necessary licenses and developing innovative digital currency trading services and payment methods to enhance user experience<ref name=":12" />. Gatecoin planned the introduction of a white-labeled debit card that could be reloaded instantly online using bitcoins, providing users with a convenient way to spend their digital currency worldwide without incurring foreign transaction fees<ref name=":12" />. | |||
Aurélien Menant was the CEO of Gatecoin through 2015 and 2016<ref name=":0">[https://old.reddit.com/r/gatecoin/comments/4jb1la/official_statement_regarding_gatecoin_hot_wallet/ OFFICIAL STATEMENT REGARDING GATECOIN HOT WALLET BREACH - Reddit] (Accessed Apr 2, 2024)</ref>. | |||
== The Reality == | == The Reality == | ||
| Line 60: | Line 58: | ||
|Palantine King Downtime Post | |Palantine King Downtime Post | ||
|Palantine King posts on their website noting that Gatecoin, a significant player in DGD trading volumes which they actively trade, abruptly went offline after displaying a maintenance page for an hour<ref name=":17">[https://web.archive.org/web/20160512205427/http://palatineking.com/2016/05/09/gatecoin-hacked/ Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT] (Accessed Apr 24, 2024)</ref>. Despite calls for tweet updates during the maintenance, none were provided, fueling speculation of a hack<ref name=":17">[https://web.archive.org/web/20160512205427/http://palatineking.com/2016/05/09/gatecoin-hacked/ Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT] (Accessed Apr 24, 2024)</ref>. While the hack remains unconfirmed, early indicatorsI suggest it as a likely scenario<ref name=":17">[https://web.archive.org/web/20160512205427/http://palatineking.com/2016/05/09/gatecoin-hacked/ Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT] (Accessed Apr 24, 2024)</ref>. Given Gatecoin's substantial role in DGD trading, the incident could have significant consequences for DGD's price, particularly if hackers engage in unbalanced selling<ref name=":17">[https://web.archive.org/web/20160512205427/http://palatineking.com/2016/05/09/gatecoin-hacked/ Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT] (Accessed Apr 24, 2024)</ref>. The situation is unfolding, and further updates are awaited<ref name=":17">[https://web.archive.org/web/20160512205427/http://palatineking.com/2016/05/09/gatecoin-hacked/ Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT] (Accessed Apr 24, 2024)</ref>. | |Palantine King posts on their website noting that Gatecoin, a significant player in DGD trading volumes which they actively trade, abruptly went offline after displaying a maintenance page for an hour<ref name=":17">[https://web.archive.org/web/20160512205427/http://palatineking.com/2016/05/09/gatecoin-hacked/ Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT] (Accessed Apr 24, 2024)</ref>. Despite calls for tweet updates during the maintenance, none were provided, fueling speculation of a hack<ref name=":17">[https://web.archive.org/web/20160512205427/http://palatineking.com/2016/05/09/gatecoin-hacked/ Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT] (Accessed Apr 24, 2024)</ref>. While the hack remains unconfirmed, early indicatorsI suggest it as a likely scenario<ref name=":17">[https://web.archive.org/web/20160512205427/http://palatineking.com/2016/05/09/gatecoin-hacked/ Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT] (Accessed Apr 24, 2024)</ref>. Given Gatecoin's substantial role in DGD trading, the incident could have significant consequences for DGD's price, particularly if hackers engage in unbalanced selling<ref name=":17">[https://web.archive.org/web/20160512205427/http://palatineking.com/2016/05/09/gatecoin-hacked/ Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT] (Accessed Apr 24, 2024)</ref>. The situation is unfolding, and further updates are awaited<ref name=":17">[https://web.archive.org/web/20160512205427/http://palatineking.com/2016/05/09/gatecoin-hacked/ Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT] (Accessed Apr 24, 2024)</ref>. | ||
|- | |||
|May 9th, 2016 2:30:43 PM MDT | |||
|Reddit Downtime Discussion | |||
|Palantine King posts their concerns about the Gatecoin downtime on Reddit<ref name=":19">[https://old.reddit.com/r/digix/comments/4ilk1p/gatecoin_hacked/d2z4m5q/ Paletine King - Gatecoin hacked? - Reddit] (Accessed Apr 24, 2024)</ref>. One user expressed that they are also having trouble with a withdrawal which hasn't come through yet<ref name=":19">[https://old.reddit.com/r/digix/comments/4ilk1p/gatecoin_hacked/d2z4m5q/ Paletine King - Gatecoin hacked? - Reddit] (Accessed Apr 24, 2024)</ref>. | |||
|- | |- | ||
|May 9th, 2016 | |May 9th, 2016 | ||
| Line 104: | Line 106: | ||
|Homepage 404 Error | |Homepage 404 Error | ||
|The present homepage is captured displaying a 404 error<ref name=":11">[https://web.archive.org/web/20160518155002/http://gatecoin.com/ Gatecoin Homepage Archive May 18th, 2016 9:50:02 AM MDT] (Accessed Apr 18, 2024)</ref>. | |The present homepage is captured displaying a 404 error<ref name=":11">[https://web.archive.org/web/20160518155002/http://gatecoin.com/ Gatecoin Homepage Archive May 18th, 2016 9:50:02 AM MDT] (Accessed Apr 18, 2024)</ref>. | ||
|- | |||
|May 20th, 2016 1:36:34 AM MDT | |||
|Update Post Made | |||
|Gatecoin provides an update regarding the hot wallet breach investigation, fund withdrawals, and frequently asked questions (FAQ)<ref>[https://twitter.com/Gatecoin/status/733564517901172736 Gatecoin - Update on Gatecoin Hot Wallet Breach Investigation, Fund Withdrawals & FAQ - Twitter] (April 25th, 2024)</ref><ref name=":20">[https://old.reddit.com/r/gatecoin/comments/4k75xq/update_on_gatecoin_hot_wallet_breach/ Update on Gatecoin Hot Wallet Breach Investigation, Fund Withdrawals & FAQ (May 20, 2016) - Reddit] (Accessed Apr 25, 2024)</ref>. The company expresses sincere apologies for the breach and appreciates the patience of clients and the community<ref name=":20">[https://old.reddit.com/r/gatecoin/comments/4k75xq/update_on_gatecoin_hot_wallet_breach/ Update on Gatecoin Hot Wallet Breach Investigation, Fund Withdrawals & FAQ (May 20, 2016) - Reddit] (Accessed Apr 25, 2024)</ref>. Notably, client data remains safe, and the investigation is ongoing with cooperation from authorities<ref name=":20">[https://old.reddit.com/r/gatecoin/comments/4k75xq/update_on_gatecoin_hot_wallet_breach/ Update on Gatecoin Hot Wallet Breach Investigation, Fund Withdrawals & FAQ (May 20, 2016) - Reddit] (Accessed Apr 25, 2024)</ref>. Progress has been made in fundraising efforts, aiming to reimburse stolen ETH and BTC funds<ref name=":20">[https://old.reddit.com/r/gatecoin/comments/4k75xq/update_on_gatecoin_hot_wallet_breach/ Update on Gatecoin Hot Wallet Breach Investigation, Fund Withdrawals & FAQ (May 20, 2016) - Reddit] (Accessed Apr 25, 2024)</ref>. Gatecoin offers a bounty for the return of stolen funds and addresses various user concerns through the FAQ section, promising updates on withdrawal availability, DGD token safety, and exchange relaunch plans<ref name=":20">[https://old.reddit.com/r/gatecoin/comments/4k75xq/update_on_gatecoin_hot_wallet_breach/ Update on Gatecoin Hot Wallet Breach Investigation, Fund Withdrawals & FAQ (May 20, 2016) - Reddit] (Accessed Apr 25, 2024)</ref>. CEO Aurélien Menant signs off with gratitude for continued patience and understanding from users<ref name=":20">[https://old.reddit.com/r/gatecoin/comments/4k75xq/update_on_gatecoin_hot_wallet_breach/ Update on Gatecoin Hot Wallet Breach Investigation, Fund Withdrawals & FAQ (May 20, 2016) - Reddit] (Accessed Apr 25, 2024)</ref>. | |||
|- | |- | ||
|May 28th, 2016 | |May 28th, 2016 | ||
Revision as of 16:21, 25 April 2024
Notice: This page is a new case study and some aspects have not been fully researched. Some sections may be incomplete or reflect inaccuracies present in initial sources. Please check the References at the bottom for further information and perform your own additional assessment. Please feel free to contribute by adding any missing information or sources you come across. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!
Gatecoin was one of the first regulated digital asset exchanges. This didn’t stop the hack of 185,000 ETH and 250 BTC. According to a forensic analysis, the exchange may have been the victim of a man-in-the-middle attack. The malicious external party involved in this breach managed to alter their system so that BTC and ETH deposit transfers bypassed the multisig cold storage and went directly to the hacker’s wallet during the breach period. The company fired their CTO, managed to raise $500k in order to reopen, and ultimately repaid all customers. They were saved by maintaining large cold wallet reserves which appear to have been properly stored, and appear to have dealt with the issue transparently. Having hot wallet insurance would have further assisted with the recovery. A system like Proof of Reserves or an automated alert system could have allowed the issue to be noted sooner.
This exchange or platform is based in Hong Kong, or the incident targeted people primarily in Hong Kong.[1]
About Gatecoin
Founded and established in 2013 in Hong Kong, Gatecoin primarily focused on Bitcoin and Ethereum markets[2]. Gatecoin was a regulated and secure financial institution specializing in blockchain assets[3]. Gatecoin emphasized compliance and transparency, boasting KYC and AML processes supported by a major compliance solutions provider[3]. In 2015, Gatecoin launched a new Bitcoin exchange which featured robust security measures[4]. These measures include segregated client bank accounts, multi-signature cold storage, and continuous monitoring by an external IT security firm[4]. The company emphasizes its commitment to regulatory compliance, operating under a Hong Kong Money Service Operator license and adhering to AML/KYC rules[4]. Gatecoin's segregated bank accounts ensure that clients' funds are kept separate from operational expenses, minimizing counterparty risks[4].
The platform promises deep liquidity through a market maker rebate program and features an instant buy/sell option for seamless currency swaps[3]. The exchange allows users to trade Bitcoin against USD, Euro, and HKD, with plans to integrate Ripple into its platform soon[4]. Users can easily buy and sell bitcoin, ether (Ethereum), and DAO tokens worldwide with various fiat currencies, benefiting from public live-data streaming, a fully documented REST API, and dedicated customer support[3]. The exchange's trading system is decentralized, modular, scalable, and highly secured, employing bank-grade security procedures and segregated client accounts[3]. Moreover, Gatecoin offers a smart and mobile-optimized interface for intuitive trading experiences, continually enhancing its platform for user convenience and efficiency[3].
Aurélien Menant was the CEO of Gatecoin through 2015 and 2016[5]. Looking ahead from 2015, Gatecoin expressed aims to expand its business to the US and Europe, focusing on obtaining the necessary licenses and developing innovative digital currency trading services and payment methods to enhance user experience[4]. Gatecoin planned the introduction of a white-labeled debit card that could be reloaded instantly online using bitcoins, providing users with a convenient way to spend their digital currency worldwide without incurring foreign transaction fees[4].
The Reality
The Gatecoin server infrastructure was insecure against outside vulnerabilities. It would also appear that Gatecoin was not monitoring their balance integrity on an ongoing basis, and was unaware of an intrusion into their system for several days.
What Happened
Between May 9th and May 12th, 2016, funds sent to Gatecoin were diverted to an external wallet controlled by an attacker.
| Date | Event | Description |
|---|---|---|
| January 30th, 2015 4:10:26 AM MST | Segregated Bank Account Launch | CoinTelegraph announces that Hong-Kong based Gatecoin Limited has launched a new Bitcoin exchange with stringent security measures, including segregated client bank accounts, multi-signature cold storage, and continuous monitoring and audit by an external IT security firm[4]. Segregated bank accounts ensure that clients' funds are kept separate from operational expenses, minimizing counterparty risks. Gatecoin CEO Aurélien Menant emphasized the rarity of this practice in the crypto space, stating that it dramatically reduces risks for clients[4]. The company, operating with a Hong Kong Money Service Operator license and complying with AML/KYC rules, has secured a unique banking structure due to its regulatory compliance[4]. Gatecoin offers trading in Bitcoin against USD, Euro, and HKD, with plans to integrate Ripple into its platform soon. Additionally, it is introducing a white-labeled debit card, usable worldwide without foreign transaction fees, reloadable with bitcoins online instantly[4]. Gatecoin aims to expand its services to the US and Europe, focusing on obtaining necessary licenses and developing innovative trading services and payment methods to enhance customer experience[4]. |
| May 9th, 2016 1:38:25 AM MDT | Bitcoin Transaction | One of the bitcoin transactions involved in the theft for 12 BTC[6]. |
| May 9th, 2016 4:01:19 AM MDT | Bitcoin Transaction | One of the bitcoin transactions involved in the theft for 1 BTC[7]. |
| May 9th, 2016 5:29:24 AM MDT | Bitcoin Transaction | One of the bitcoin transactions involved in the theft for 200 BTC[8]. |
| May 9th, 2016 12:14:07 PM MDT | Bitcoin Transaction | One of the bitcoin transactions involved in the theft for 45.6 BTC[9]. |
| May 9th, 2016 12:23:11 PM MDT | Bitcoin Transaction | A smaller bitcoin transaction involved in the theft for 6.18 BTC[10]. |
| May 9th, 2016 12:38:16 PM MDT | Bitcoin Transaction | A smaller bitcoin transaction involved in the theft for 2.12 BTC[11]. |
| May 9th, 2016 1:54:26 PM MDT | Palantine King Downtime Post | Palantine King posts on their website noting that Gatecoin, a significant player in DGD trading volumes which they actively trade, abruptly went offline after displaying a maintenance page for an hour[12]. Despite calls for tweet updates during the maintenance, none were provided, fueling speculation of a hack[12]. While the hack remains unconfirmed, early indicatorsI suggest it as a likely scenario[12]. Given Gatecoin's substantial role in DGD trading, the incident could have significant consequences for DGD's price, particularly if hackers engage in unbalanced selling[12]. The situation is unfolding, and further updates are awaited[12]. |
| May 9th, 2016 2:30:43 PM MDT | Reddit Downtime Discussion | Palantine King posts their concerns about the Gatecoin downtime on Reddit[13]. One user expressed that they are also having trouble with a withdrawal which hasn't come through yet[13]. |
| May 9th, 2016 | Breach Begin | The reported date that that breach began[14] at "late night HKT"[5]. There was a "disruption of [the Gatecoin] service caused by a server reboot"[5]. They "strongly believe that the breach is linked to this event"[5]. |
| May 10th, 2016 10:04:00 AM MDT | Palantine King False Alarm | Palantine King posts the final update to their website, concluding that there was no problem with the Gatecoin exchange other than a temporary server outage, based largely on official information received from Gatecoin[12]. |
| May 12th, 2016 | Breach Ended | The reported date that the breach ended on "Thursday evening HKT"[5]. |
| May 13th, 2016 | Cited Date | The date of the hack cited by Kyle Gibson[15]. On "Friday night HKT" is when the team "detected some suspicious transactions and immediately suspended [thei]r services to investigate"[5]. |
| May 13th, 2016 4:50:00 PM MDT | CoinDesk Article Released | CoinDesk reports that Gatecoin faces turmoil after reportedly experiencing a hack, resulting in losses from its connected wallets[16]. CEO Aurélien Menant confirmed the incident and assured users of efforts to refund customers affected by the breach[16]. Users are faced with uncertainty and concern regarding the security of their funds[16]. Gatecoin's assurance of conducting a full forensic investigation to identify the root cause of the issue is a positive step, but the timeline for resolution and the extent of the losses remain unclear[16]. |
| May 14th, 2016 5:22:56 AM MDT | Official Statement Released On Reddit | In a Reddit post, Gatecoin confirmed a breach of its system resulting in the loss of 15% of its crypto-asset deposits, valued at approximately $2 million[5]. The breach occurred between May 9 and May 12, 2016, with suspicious transactions detected on May 13 prompting the suspension of services. Despite storing most funds in multi-signature cold wallets, hackers bypassed this security measure, diverting ETH and BTC deposits to hot wallets during the breach. Gatecoin plans to release a platform for clients to withdraw remaining funds by May 28, 2016, with the exact date for ETH withdrawals pending confirmation. The exchange assures the security of DGD, REP, and DAO funds, while working to raise additional funds to reimburse affected customers. Gatecoin expresses gratitude for community support and pledges to provide updates via Twitter, Reddit, and its homepage[5]. |
| May 14th, 2016 5:37:00 AM MDT | Official Statement On Twitter and Homepage | An update is provided on Twitter, which links to the Gatecoin homepage as an official statement about the hack[17]. The Gatecoin homepage is later captured providing an official statement about the breach. Loss figures are provided as 15% of its crypto-asset deposits, totaling ETH 185,000 and BTC 250 (equivalent to USD 2 million) between May 9 and May 12, 2016[18]. The breach occurred due to a system alteration that allowed ETH and BTC deposits to bypass multi-signature cold storage and go directly to the hot wallet[18]. The compromised wallet addresses and Bitcoin transactions have been identified[18]. Gatecoin suspended its services upon detecting suspicious transactions and is working with Tehtri Security to investigate the breach thoroughly[18]. A platform enabling clients to withdraw remaining funds in various currencies will be released, and efforts are underway to raise additional funding to cover losses and reimburse affected customers[18]. Gatecoin expresses gratitude for the community's support and pledges to provide updates through various channels[18]. |
| May 16th, 2016 3:11:00 AM MDT | Gatecoin on Withdrawal Of REP Tweet | A Gatecoin agent account responds to a customer inquiry about the ability to withdraw the REP tokens from their account[19]. They note that they are planning to build a custom interface to facilitate these withdrawals by March 28th[19]. |
| May 16th, 2016 10:27:00 AM MDT | CoinDesk Article On Breach | CoinDesk reports that Gatecoin has disclosed the cyberattack on its hot wallets, with the loss of funds estimated at $2 million[14]. The breach, believed to have begun on May 9th and continued for three days, led to the theft of 185,000 ethers and 250 bitcoins. Gatecoin acknowledged that its security measures, including multi-signature cold wallets, were compromised, allowing funds to bypass cold storage and go directly to hot wallets during the breach. The incident coincided with TheDAO's crowdsale, raising concerns about the security of Ethereum-based tokens[14]. Gatecoin plans to establish a portal for withdrawing DAO-related tokens in two weeks but did not specify a timeline for processing bitcoin and ether withdrawals[14]. |
| May 18th, 2016 9:50:02 AM MDT | Homepage 404 Error | The present homepage is captured displaying a 404 error[20]. |
| May 20th, 2016 1:36:34 AM MDT | Update Post Made | Gatecoin provides an update regarding the hot wallet breach investigation, fund withdrawals, and frequently asked questions (FAQ)[21][22]. The company expresses sincere apologies for the breach and appreciates the patience of clients and the community[22]. Notably, client data remains safe, and the investigation is ongoing with cooperation from authorities[22]. Progress has been made in fundraising efforts, aiming to reimburse stolen ETH and BTC funds[22]. Gatecoin offers a bounty for the return of stolen funds and addresses various user concerns through the FAQ section, promising updates on withdrawal availability, DGD token safety, and exchange relaunch plans[22]. CEO Aurélien Menant signs off with gratitude for continued patience and understanding from users[22]. |
| May 28th, 2016 | Withdrawal Platform Promised | The original Reddit announcement promised a withdrawal site would be made available on May 28th[5]. The promised withdrawals were for remaining funds in BTC, DAO, DGD, REP, USD, EUR and HKD[5]. |
| June 20th, 2016 2:07:35 AM MDT | Freezing Ethereum Wallets | A Reddit thread discusses freezing the hacker's ethereum wallet addresses, since they are known at the time[23]. |
| September 15th, 2017 | Gatecoin Banking Freeze | Gatecoin bank accounts are frozen without prior notice being provided[24]. Details about the suspension were not provided in a phone call the exchange received from a Hang Seng Bank representative at the time[25]. |
| November 20th, 2017 4:46:00 AM MST | CoinTelegraph Banking Freeze Report | CoinTelegraph reports on Gatecoin losing its banking services[24]. Despite the surge in customer base and Bitcoin price rally, Gatecoin experienced a banking freeze in September without prior notice, forcing it to seek foreign banking support to continue operations[24]. This incident highlights the challenges faced by cryptocurrency businesses in accessing banking services, with many relying on foreign banks to operate amidst domestic restrictions[24]. Additionally, the resistance from Hong Kong's banking sector contrasts with its interest in blockchain technology, as evidenced by the participation of twenty local banks in a trade network with Singapore utilizing blockchain[24]. |
| March 2nd, 2019 11:00:14 PM MST | Bloomberg Banking Services Issues | Using Gatecoin as an example, Bloomberg reports that crypto companies are facing challenges in accessing basic banking services from mainstream institutions like HSBC and JPMorgan Chase, despite attracting investments from large institutions[26]. This issue persists globally, from New York to Hong Kong, hindering the growth and development of the digital-assets industry[26]. |
| March 13th, 2019 12:26:16 PM MDT | Reddit Thread On Bankruptcy | A Reddit thread discusses a liquidation of Gatecoin[27]. Users are frustrated and unable to access their funds[27]. Some users suspect foul play, while others scramble to recover whatever they can[27]. The situation sparks a mix of anger, desperation, and a few glimmers of hope for resolution[27]. |
| March 14th, 2019 8:50:00 AM MDT | CoinTelegraph Article On Bankruptcy | CoinTelegraph reports that following ongoing banking problems and a tumultuous history marked by a major hack in May 2016, Hong Kong-based cryptocurrency exchange Gatecoin has been ordered to undergo compulsory liquidation[28]. The exchange, which lost around $2 million in cryptocurrencies during the hack, announced its winding-up order on March 13, leading to an immediate cessation of operations. Gatecoin attributed its financial difficulties to issues with a Payment Service Provider (PSP), which it claimed failed to process transfers promptly, causing substantial losses and ultimately rendering the exchange unable to sustain its operations[28]. Despite efforts to recover funds and mitigate losses, Gatecoin's struggles persisted, leading to its final liquidation[28]. |
| March 14th, 2019 7:00:17 PM MDT | CoinDesk Article On Bankruptcy | CoinDesk reports that Hong Kong-based cryptocurrency exchange Gatecoin is set to cease operations and enter liquidation following a prolonged struggle to recover funds lost amid a dispute with a former payment services provider[29]. The announcement, made via the company's website, cited ongoing banking issues since September 2018 as a primary reason for the shutdown[29]. Despite efforts to resume operations with alternative processors and banks, Gatecoin faced insurmountable challenges, leading to a court order to wind up immediately[29]. The exchange assured customers of its intent to distribute remaining assets to creditors but left uncertainties regarding reimbursement for those affected by the 2016 cyberattack that resulted in the loss of significant cryptocurrency holdings[29]. |
| April 1st, 2019 2:45:11 AM MDT | TheNextWeb Article | TheNextWeb reports on Gatecoin has finally met its demise as liquidators take control of the company after facing a series of hacking incidents and banking troubles[2]. Established in 2013 in Hong Kong, Gatecoin primarily focused on Bitcoin and Ethereum markets. However, in 2016, it suffered a significant loss of 185,000 ETH and 250 BTC due to a hack on its hot wallets, followed by banking disruptions in 2017 when its Hong Kong-based accounts were frozen[2]. With the appointment of official liquidators, Gatecoin's journey comes to a definitive end, marking the closure of one of the pioneering exchanges in the cryptocurrency landscape[2]. |
Technical Details
The breach occurred due to a system alteration that allowed ETH and BTC deposits to bypass multi-signature cold storage and go directly to the hot wallet[18].
Breach Of Multi-Signature Systems
"We have previously communicated the fact that most clients’ crypto-asset funds are stored in multi-signature cold wallets. However, the malicious external party involved in this breach, managed to alter our system so that ETH deposit transfers by-passed the multi-sig cold storage and went directly to the hot wallet during the breach period. This means that losses of ETH funds exceed the 5% limit that we imposed on our hot wallets."
Wallets Used By Thief
The forensic examination identified several wallets and transactions which were involved in the theft[5]:
- Wallet 0x1HnJry8tmN4BW5UFqYR8L4xWgtJZ7ghExU (Unmentioned)
- Transaction 2f41b858712149df089c21d4e1c036e0a465335c5a29be38df8e945a51e4d809[8]
- Wallet 0x04786aada9deea2150deab7b3b8911c309f5ed90
- Wallet 0xc062dceed93087c9112ff7b02d53e928e49cec09
- Wallet 0x1342a001544b8b7ae4a5d374e33114c66d78bd5f
- Transaction 4a1b96b166de37860195af37b6396a0516b009536e0f332006ca61b4fab0cd08[9]
- Wallet 0xd4914762f9bd566bd0882b71af5439c0476d2ff6
- Wallet 0x132ymu2ufMP3mDCo9qwKc173PV2Bbm4T2g (Unmentioned)
- Transaction d494c7ca3a03f30c121b02f558b068d3597092454ad325bc320383f070d536bc[6]
- Transaction 90622fc9968b79c90a9ac26f11d13d8dd97ba5b7e9c103594873e6306f7357ea[7]
- Transaction 271c51ff2e6c84c565c94d79872a79d77726fccd47192b6c8f6745f7482e281a[10]
- Transaction 435e0cc79372eef5f43d8d81320940165ea1a0828adab3fdb9822a17caffaf2b[11]
Total Amount Lost
On May 14th, Gatecoin announced that the losses were 15% of their client funds with a total of 185,000 ETH and 250 BTC reported[5]. News sources such as CoinDesk and TheNextWeb reported the full loss amount[14][2].
Kyle Gibson reported only the amount at 250 bitcoin, with an estimated value of $2,500,000 USD[15]. The theft of any Ethereum amount was not mentioned in his report[15].
Gatecoin stated that the lost cryptocurrency was "equivalent to USD 2 million" in their Reddit post[5]. According to CoinTelegraph, the amount lost "during the hack" was "around $2 million in cryptocurrencies"[28]. CoinDesk estimated that amount as $2.14m at "press time"[14].
| BTC | Transaction | Wallet |
|---|---|---|
| 12 | d494c7ca3a03f30c121b02f558b068d3597092454ad325bc320383f070d536bc | 132ymu2ufMP3mDCo9qwKc173PV2Bbm4T2g |
| 1 | 90622fc9968b79c90a9ac26f11d13d8dd97ba5b7e9c103594873e6306f7357ea | 132ymu2ufMP3mDCo9qwKc173PV2Bbm4T2g |
| 200 | 2f41b858712149df089c21d4e1c036e0a465335c5a29be38df8e945a51e4d809 | 1HnJry8tmN4BW5UFqYR8L4xWgtJZ7ghExU |
| 45.6 | 4a1b96b166de37860195af37b6396a0516b009536e0f332006ca61b4fab0cd08 | 1342a001544b8b7ae4a5d374e33114c66d78bd5f |
| 6.18 | 271c51ff2e6c84c565c94d79872a79d77726fccd47192b6c8f6745f7482e281a | 132ymu2ufMP3mDCo9qwKc173PV2Bbm4T2g |
| 2.12 | 435e0cc79372eef5f43d8d81320940165ea1a0828adab3fdb9822a17caffaf2b | 132ymu2ufMP3mDCo9qwKc173PV2Bbm4T2g |
The total amount lost has been estimated at $2,500,000 USD.
Immediate Reactions
Gatecoin promptly shut down its exchange and ports after suspecting a potential leak in its hot wallets and started an investigation[16]. Gatecoin communicated with its users through various channels, including Slack and Twitter[16]. CEO Aurélien Menant provided updates via Slack, informing users about the incident and the measures being taken to address it[16]. Gatecoin provided updates on the status of its website through Twitter, informing users about the high risk of a leak in some of its hot wallets and the decision to take the website offline as a precautionary measure[16].
Forensic Security Examination
The platform initiated a full forensic investigation to identify the root cause of the issue and determine the extent of the breach[16]. Gatecoin involved the services of third party Tehtri Security to conduct a forensic examination[5].
CoinDesk Article and Statement
CoinDesk was one of the first to report on the hack[16]. Gatecoin issued a statement to CoinDesk, acknowledging the suspected leak in its hot wallets and the decision to shut down the exchange and ports as a precautionary measure[16]. The statement outlined the ongoing forensic investigation and the exchange's commitment to minimizing further potential losses[16].
"News emerged last week of yet another security event in the digital currency exchange ecosystem, this time impacting a Hong Kong-based service involved in the sale of assets related to Ethereum-based decentralized autonomous organizations (DAOs). As reported on Friday, Gatecoin experienced a cyberattack on its hot wallets that resulted in the loss of funds. A new update from the exchange team indicated that as much as $2m was lost, confirming rumors that circulated soon after the hack became apparent."[15]
Updates To Homepage
An update was provided on the Gatecoin homepage. It highlighted the loss of 15% of its crypto-asset deposits, totaling USD 2 million in Ethereum and Bitcoin, between May 9 and May 12, 2016[18]. This breach was attributed to a system alteration that allowed deposits to bypass multi-signature cold storage and go directly to the hot wallet[18]. In response, Gatecoin suspended its services, initiated a forensic investigation with Tehtri Security, and identified the compromised wallet addresses and Bitcoin transactions[18]. To mitigate the impact on users, Gatecoin plans to release a bespoke platform for fund withdrawals and is working to raise additional funding to cover losses and reimburse affected customers[18]. They express gratitude for the community's support and pledge to provide updates through various communication channels[18]. The homepage later appeared to be offline with a 404 error[20].
Official Statement On Reddit
On May 14th, a day after noticing the suspicious transactions and shutting down their services, Gatecoin issued a public statement through Reddit[5].
The Gatecoin team greatly appreciates the patience of all users and stakeholders while we work with Tehtri Security to confirm all of the details related to the breach and ensure that our systems can be moved to a new, clean, thoroughly tested, and monitored infrastructure before services can resume.
We sincerely apologize for all the concern experienced by our clients and for the inconvenience caused while clients wait for their fund withdrawals to be processed. Gatecoin would also like to express our gratitude to the community of exchanges that have very kindly volunteered to help identify the parties responsible for the stolen funds.
Ultimate Outcome
Gatecoin experienced significant banking disruptions in 2017, and ultimately entered bankruptcy in 2019. The exchange is remembered in various historical records.
Banking Disruptions in 2017
Gatecoin experienced banking disruptions in September 2017[25] when its Hong Kong-based bank accounts at Hang Seng Bank[25] were frozen[2] without any prior notice[24]. The bank representative who phoned with the news was not able to provide details about the suspension at the time[25]. The exchange subsequently moved to use a foreign bank based in Singapore[24][25].
Exchange Enters Bankruptcy
Hong Kong-based cryptocurrency exchange Gatecoin was reportedly ordered to undergo compulsory liquidation on March 13th, 2019, although the court issuing the order was not specified[29][28]. The exchange announced its winding-up order on March 13, leading to an immediate cessation of operations[28]. Gatecoin attributed its financial difficulties to issues with a Payment Service Provider (PSP), which it claimed failed to process transfers promptly, causing substantial losses and ultimately rendering the exchange unable to sustain its operations[28]. TheNextWeb reported on April 1st that Gatecoin had finally met its demise as liquidators take control of the company after facing a series of hacking incidents and banking troubles[2]. Despite efforts to recover funds and mitigate losses, Gatecoin's struggles persisted, leading to its final liquidation[28]. With the appointment of official liquidators, Gatecoin's journey comes to a definitive end, marking the closure of one of the pioneering exchanges in the cryptocurrency landscape[2].
CoinDesk reports that Hong Kong-based cryptocurrency exchange Gatecoin is set to cease operations and enter liquidation following a prolonged struggle to recover funds lost amid a dispute with a former payment services provider. The announcement, made via the company's website, cited ongoing banking issues since September 2018 as a primary reason for the shutdown[29]. Despite efforts to resume operations with alternative processors and banks, Gatecoin faced insurmountable challenges, leading to a court order to wind up immediately[29]. The exchange assured customers of its intent to distribute remaining assets to creditors but left uncertainties regarding reimbursement for those affected by the 2016 cyberattack that resulted in the loss of significant cryptocurrency holdings[29].
Inclusion On Hack Lists
The attack was included on lists put together by Kyle Gibson[15], BitcoinExchangeGuide.com[30], and SlowMist[31].
Total Amount Recovered
Gatecoin reassured users from the start that it would seek to refund customers following the loss[16]. While the CEO initially indicated uncertainties regarding the exact amount of funds taken, Gatecoin affirmed its intention to refund affected users[16].
There do not appear to have been any funds recovered in this case.
Ongoing Developments
The Gatecoin platform declared bankruptcy.
Individual Prevention Policies
When using any third party custodial platform (such as for trading), it is important to verify that the platform has a full backing of all assets, and that assets have been secured in a proper multi-signature wallet held by several trusted and trained individuals. If this can't be validated, then users should avoid using that platform. Unfortunately, most centralized platforms today still do not provide the level of transparency and third party validation which would be necessary to ensure that assets have been kept secure and properly backed. Therefore, the most effective strategy at present remains to learn proper self custody practices and avoid using any third party custodial platforms whenever possible.
Store the majority of funds offline. By offline, it means that the private key and/or seed phrase is exclusively held by you and not connected to any networked device. Examples of offline storage include paper wallets (seed phrase or key written down and deleted from all electronic media), hardware wallets, steel wallet devices, etc...
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
All aspects of any platform should undergo a regular validation/inspection by experts. This validation should include a security audit of any smart contracts, reporting any risks to the backing (of any customer assets, ensuring treasuries or minting functions are properly secured under the control of a multi-signature wallet, and finding any inadequacies in the level of training or integrity of the team. The recommended interval is twice prior to launch or significant system upgrade, once after 3 months, and every 6 months thereafter. It is recommended that the third party performing the inspection not be repeated within a 14 month period.
Work with other industry platforms to set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
All platforms should undergo published security and risk assessments by independent third parties. Two assessments are required at founding or major upgrade, one after 3 months, and one every 6 months thereafter. The third parties must not repeat within the past 14 months. A risk assessment needs to include what assets back customer deposits and the risk of default from any third parties being lent to. The security assessment must include ensuring a proper multi-signature wallet, and that all signatories are properly trained. Assessments must be performed on social media, databases, and DNS security.
Set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services within the country, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ https://twitter.com/search?q=(from%3AGatecoin)%20until%3A2016-06-01%20since%3A2016-05-06&src=typed_query
- ↑ 2.0 2.1 2.2 2.3 2.4 2.5 2.6 2.7 Liquidators put the final nail in Gatecoin’s coffin - TheNextWeb (Feb 3, 2020)
- ↑ 3.0 3.1 3.2 3.3 3.4 3.5 Gatecoin Homepage Archive May 5th, 2016 6:39:51 AM MDT (Accessed Apr 18, 2024)
- ↑ 4.00 4.01 4.02 4.03 4.04 4.05 4.06 4.07 4.08 4.09 4.10 4.11 Gatecoin Launches Bitcoin Exchange with ‘Segregated Bank Accounts’ - CoinTelegraph
- ↑ 5.00 5.01 5.02 5.03 5.04 5.05 5.06 5.07 5.08 5.09 5.10 5.11 5.12 5.13 5.14 OFFICIAL STATEMENT REGARDING GATECOIN HOT WALLET BREACH - Reddit (Accessed Apr 2, 2024)
- ↑ 6.0 6.1 Theft Transaction Of 12 BTC - Blockchain.com (Accessed Apr 17, 2024)
- ↑ 7.0 7.1 Theft Transaction Of 1 BTC - Blockchain.com (Accessed Apr 17, 2024)
- ↑ 8.0 8.1 Theft Transaction Of 200.00000000 BTC - Blockchain.com (Accessed Apr 17, 2024)
- ↑ 9.0 9.1 Theft Transaction Of 45.60000000 BTC - Blockchain.com (Accessed Apr 17, 2024)
- ↑ 10.0 10.1 Theft Transaction Of 6.18 BTC - Blockchain.com (Accessed Apr 17, 2024)
- ↑ 11.0 11.1 Theft Transaction Of 2.12 BTC - Blockchain.com (Accessed Apr 17, 2024)
- ↑ 12.0 12.1 12.2 12.3 12.4 12.5 Gatecoin hacked - Palantine King Archive May 12th, 2016 2:54:27 PM MDT (Accessed Apr 24, 2024)
- ↑ 13.0 13.1 Paletine King - Gatecoin hacked? - Reddit (Accessed Apr 24, 2024)
- ↑ 14.0 14.1 14.2 14.3 14.4 14.5 14.6 Gatecoin Claims $2 Million in Bitcoins and Ethers Lost in Security Breach - CoinDesk
- ↑ 15.0 15.1 15.2 15.3 15.4 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents - Kyle Gibson (Jan 25, 2020)
- ↑ 16.00 16.01 16.02 16.03 16.04 16.05 16.06 16.07 16.08 16.09 16.10 16.11 16.12 16.13 Digital Currency Exchange Gatecoin Offline After Loss of Funds - CoinDesk (Accessed Apr 23, 2024)
- ↑ Gatecoin - "SERVICE UPDATE: Official Statement Regarding Gatecoin Hot Wallet Breach. Read here" - Twitter (Accessed Apr 24, 2024)
- ↑ 18.00 18.01 18.02 18.03 18.04 18.05 18.06 18.07 18.08 18.09 18.10 18.11 Gatecoin Homepage Official Statement Archive May 14th, 2016 9:09:20 AM MDT (Accessed Apr XX, 2024)
- ↑ 19.0 19.1 Gatecoin - "we will build a custom platform for REP, DAO, DGD and fiat withdrawals for release on or before May 28." - Twitter (Accessed Apr 23, 2024)
- ↑ 20.0 20.1 Gatecoin Homepage Archive May 18th, 2016 9:50:02 AM MDT (Accessed Apr 18, 2024)
- ↑ Gatecoin - Update on Gatecoin Hot Wallet Breach Investigation, Fund Withdrawals & FAQ - Twitter (April 25th, 2024)
- ↑ 22.0 22.1 22.2 22.3 22.4 22.5 Update on Gatecoin Hot Wallet Breach Investigation, Fund Withdrawals & FAQ (May 20, 2016) - Reddit (Accessed Apr 25, 2024)
- ↑ gatecoin's hacked ether addresses are known, do we freeze them too? - Reddit (Accessed Apr 23, 2024)
- ↑ 24.0 24.1 24.2 24.3 24.4 24.5 24.6 Banks Shun Bitcoin In Hong Kong, Businesses Seek Foreign Help - CoinTelegraph (Accessed Apr 8, 2024)
- ↑ 25.0 25.1 25.2 25.3 25.4 Hong Kong’s bitcoin businesses suffer after local bank accounts frozen - SCMP (Accessed Apr 8, 2024)
- ↑ 26.0 26.1 Why Crypto Companies Still Can’t Open Checking Accounts - Bloomberg (Accessed Apr 23, 2024)
- ↑ 27.0 27.1 27.2 27.3 kuilef - "gatecoin liquidated :(" - Reddit (Accessed Apr 23, 2024)
- ↑ 28.0 28.1 28.2 28.3 28.4 28.5 28.6 28.7 Previously Hacked Gatecoin Exchange Receives Liquidation Order Following Banking Problems - CoinTelegraph (Feb 3, 2020)
- ↑ 29.0 29.1 29.2 29.3 29.4 29.5 29.6 29.7 Gatecoin Crypto Exchange to Shut Down on Court’s Orders - CoinDesk (Feb 3, 2020)
- ↑ Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com (Mar 5, 2020)
- ↑ SlowMist Hacked - SlowMist Zone (Jun 26, 2021)