BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Gate Security Course 01 | Gate & BlockSec: How to Prevent Account Theft, Phishing, and Identity Impersonation

大门安全课
特邀专栏作者
This article is about 11062 words, reading the full article takes about 16 minutes
Gate's special series "Gate Security Course" provides dedicated answers to different types of crypto security issues. Starting from the most real cases that happen around users, we collaborate with professional institutions in the security field to offer dual perspectives from both the platform side and the security side, systematically breaking down security rules from basic to advanced. While educating users on security awareness, we help users build a truly effective line of defense starting from themselves.
AI Summary
Expand
  • Core Viewpoint: Social engineering attacks have become the type of risk causing the greatest losses in the Web3 industry despite being low in technical sophistication. Attackers do not crack code or cryptography; instead, they exploit trust, greed, and negligence to trick users into voluntarily completing transfers or signatures. Therefore, security defenses must expand from "preventing code vulnerabilities" to "preventing judgment failures."
  • Key Elements:
    1. Common social engineering attacks fall into five categories: takeover of real social media accounts, targeted fraud after SIM Swap, long-term relationship cultivation to induce investment, recruitment or business bait to plant malware, and impersonation of exchange customer support.
    2. In the Cheng v. T-Mobile case, attackers used SIM Swap to take over a real Telegram account and tricked the victim into transferring 15 BTC; the GrassCall attack used fake Web3 online interviews to plant data-stealing programs.
    3. Gate's risk control features four gates: login, withdrawal, fiat off-ramp method toggle, and a cooling-off period for security settings. New withdrawal addresses have a 24-to-48-hour cooling-off period, and simultaneously changing 2FA or password will lock withdrawals across the entire account.
    4. In insider-facilitated attacks, traditional identity verification may fail, with system traces all pointing to "the user's own operation." Therefore, Passkey (naturally phishing-resistant, domain-bound, requires biometric verification) and Gate Ukey physical keys are recommended.
    5. Principles for handling a compromised account: first use a trusted device to block access, check the upstream email and phone, publish a risk warning, move remaining assets, and preserve evidence such as transaction hashes, attacker addresses, and chat records.
    6. On-chain funds are traceable but not necessarily recoverable, requiring collaboration among exchanges, stablecoin issuers, security firms, and law enforcement agencies; Gate's reserve ratio is 127%, with a scale of $8.215 billion, audited by Hacken and open-sourced.
    7. Hardening recommendations: fourfold isolation of identity, devices, assets, and verification channels; large transactions should be confirmed through a second channel; stay alert to induced commands such as "the camera isn't working" or "update the Zoom plugin."

Let me start with a question.

Your business partner sends you a message on Telegram: the company's payment address has changed, please send this period's payment to the new address; they also attach a stamped confirmation letter. What would you do first?

If your answer is "send first, verify later," this article is for you. Many asset losses do not begin with a complex piece of code or a system intrusion. Attackers don't need to break blockchain cryptography or crack encryption. They only need to exploit your goodwill and trust, or trigger your greed and carelessness.

This is also the first installment of Gate's specially curated "Gate Security Course." We invited blockchain security firm BlockSec and the Gate security team to discuss, from the perspectives of a security firm and a trading platform, the type of attack that causes the most losses in this industry yet is often not particularly sophisticated: account theft phishing, social engineering, and insider attacks.

Guest Introduction

Professor Zhou Yajin of BlockSec: Professor Zhou Yajin is an associate professor at the Chinese University of Hong Kong and co-founder of blockchain security firm BlockSec. He has published over 50 high-level papers at top international security conferences and journals, with over 10,000 citations. He is currently exploring how to reconstruct system infrastructure to improve the efficiency and security of AI agents.

BlockSec was founded in 2021 and focuses on blockchain security and compliance, covering three areas: on-chain security protection, fund tracing and investigation, and digital asset compliance. It currently serves over 1,000 clients globally, has protected over $50 billion in on-chain assets cumulatively, maintains an illegal address label database of over 600 million entries, and has fully reconstructed the largest single case involving $1.6 billion in funds.

Gate Security Team: Hello everyone, we're glad to launch this column. The Gate security department is responsible for building the platform's account, trading, and asset security systems, and also handles user appeals regarding abnormal accounts and coordination requests on an ongoing basis.

Gate was founded in 2013 and was the first platform in the industry to launch 100% proof of reserves. It currently serves over 60 million users worldwide. To us, security is not an add-on feature but the prerequisite for whether this business can exist at all. Through "Gate Security Course," we hope to clearly explain the common mechanisms behind these real risks.

Q1. Could you share some real cases of social engineering theft? How are accounts stolen? What are the main methods?

Professor Zhou Yajin of BlockSec: The core characteristic of social engineering attacks is that the attacker does not directly break through the blockchain's underlying layer, smart contracts, or cryptographic mechanisms, but instead controls identity, communication channels, or exploits existing trust relationships to induce victims to voluntarily complete transfers, signatures, authorizations, or install malicious programs. There are five common categories.

1) Social media account takeover. Attackers don't fake accounts; they directly control real accounts and use their long-accumulated influence to promote tokens or phishing links. A real account does not mean the information it sends at this moment is also real.

2) Targeted fraud after communication channel takeover. The Cheng v. T-Mobile case disclosed in U.S. federal court documents is a typical example: attackers used SIM Swap to control a phone number, then took over a real Telegram account, and leveraging the existing Bitcoin trading relationship between the two parties, induced the victim to transfer 15 BTC under the pretext of buying above market price. The account is real, the contact is real, and the historical cooperation is real, but the person issuing the instruction at this moment is no longer the same person.

3) Long-term relationship cultivation followed by investment inducement. Attackers enter the victim's daily social circle as friends, investment advisors, tenants, or potential partners, building trust over months or even longer, then directing them to log into fake investment platforms. This type of attack doesn't require stealing any account; the attacker actively becomes someone you trust.

4) Using recruitment or business cooperation as bait to plant malware. In the GrassCall attack disclosed in 2025, attackers posed as Web3 online interviews and required downloading conference software, which actually contained spyware targeting browser credentials and crypto wallets. Similar cases include inducing users to run terminal commands under the pretext of "the camera isn't working" or "you need to update the Zoom plugin."

Gate Security Team: Of the five categories Professor Zhou outlined, we have encountered almost every one in our appeal handling. This is highly consistent with what we see in appeals and coordination requests: attackers often don't need to breach the exchange system.

Because our platform's security defenses are very thick, for example: real-time threat detection with AI and machine learning, full-chain encrypted transmission, distributed traffic scrubbing, Anycast and DNSSEC deployment—these are all continuously running. But social engineering attacks don't breach these platform-side security defenses; they operate by obtaining the user's own private information. This is also why we're doing this column. Some risks can be solved by platform hardening, while others must be identified by users themselves—and the latter is precisely the type of attack that causes the greatest losses.

At the same time, let me add two perspectives that we can only see from the trading platform side.

The first is the illusion of frequency. Celebrity account hacks that make the news are all big cases, but from the tickets we receive at the exchange, the truly high-frequency incidents are not these celebrities but ordinary people. Stolen Telegram accounts asking acquaintances for payments, changing cooperation receiving addresses, or impersonating project teams to publish fake Mint addresses, and so on. A single amount might be only a few thousand dollars, with no media coverage, but the volume far exceeds the former, and users hope we can help intercept the transactions.

The second is: impersonating exchange customer service. Attackers disguise themselves as Gate customer service and contact users via email, SMS, or social platform DMs, usually citing account anomalies, verification requirements, or a pending withdrawal to confirm. To address this, we provide two tools you can start using immediately.

First is the official verification channel, where we can directly check whether any domain or contact email belongs to Gate officially. We hope users develop a habit: upon receiving any message claiming to be from Gate, check here first—this action takes only十几 seconds.

Second is the anti-phishing code. This is a string of characters set by the user themselves, and all emails sent by Gate will carry it. Conversely, any "Gate email" without this string is forged. The value of this mechanism is that it doesn't depend on the user's judgment. Users don't need to distinguish the extra letter in the sender's domain, nor judge whether the wording sounds official—they only need to see whether the code they set is there.

Q2. After a celebrity account is hacked and posts a token contract address, or a friend's account appears to be compromised, how should ordinary users verify and act most safely?

Professor Zhou Yajin of BlockSec: First, a basic principle must be established: account authenticity and information authenticity must be verified separately. Even if the information comes from a verified official account, project account, celebrity account, or a long-contacted acquaintance's account, high-risk operations should not be executed solely based on account identity. This is especially true for purchasing newly issued tokens, connecting wallets, signing on-chain transactions, and granting Token Approvals, which require extra caution.

For token contract addresses suddenly posted by celebrities or project teams, you can verify from the following dimensions.

1) Cross-channel verification. Do not rely only on a single X, Telegram, Discord, or WeChat account. Check the official website, other official social media channels, community announcements, and trusted third-party information sources simultaneously. If a project suddenly announces a new Token, Airdrop, or Mint but the official website and other official channels have no corresponding information at all, this itself should be treated as an anomaly signal.

2) Verify on-chain assets and contract status. Pay attention to contract deployment time, Deployer address, liquidity scale, Holder concentration, whether there are obvious fund connections between major addresses, and whether there are rapid pump-and-dump behaviors. Ordinary users don't necessarily need to complete professional-level on-chain investigations, but should at least conduct basic checks through trusted blockchain explorers and security tools.

3) Don't front-run without confirmation. Social engineering attacks rely heavily on FOMO and urgency. Messages like "ending soon," "limited-time claim," and "buy now or miss out" essentially compress the user's time to verify information. For new assets that haven't been fully verified, waiting and confirming is usually safer than front-running.

If a friend, partner, or colleague suddenly requests a transfer or changes the receiving address, verification should be done through a second channel independent of the original communication channel. For example: after receiving a transfer request on Telegram, confirm by phone; after receiving a receiving address change notice by email, verify through previously confirmed contact methods; before large transfers, reconfirm the address and conduct a small test transaction first. The most important principle is: do not complete both instruction initiation and identity verification within the same communication channel that may already be controlled by the attacker.

Q3. As a centralized exchange, how do the account risks Gate sees differ from on-chain wallet theft? What additional protections can the platform provide?

Gate Security Team: The most fundamental difference is time. For on-chain wallet theft, from signature to asset transfer is completed in one step, in seconds, final, with no intermediate step to intervene. But within the trading platform, from someone obtaining the user's login credentials to assets actually leaving the user's account, there are many steps in between. For example, Gate's account security is designed around four stages: login, trading, withdrawal, and security settings. Each stage has independent verification methods, and risk doesn't flow through unimpeded. These specifically include:

1) Login stage. Login password, email, SMS, Google Authenticator, and IP address monitoring. When an unusual login location appears, the system provides a prompt, and the value of this prompt lies in its timeliness. The account also has a security log that records the history of logins and key operations—this is the most direct self-check entry point when anomalies are suspected.

2) Withdrawal stage. The fund password is a credential independent of the login state and does not participate in daily login. This means that even if someone obtains the user's login access, they are still one credential short—one that has never appeared in the login process—from moving the user's money. In addition, at the withdrawal stage, dynamic verification is applied based on environmental changes, amount, and comprehensive account risk, and high-risk withdrawals trigger strict verification to ensure assets are not easily stolen.

3) Withdrawal method switches. Channels not needed temporarily can be turned off first—one less channel means one less exploitable exit. When needed, they can be reopened after identity verification, without affecting the normal experience.

4) Security settings stage. This layer has a mechanism many users don't know about but which is most critical in this type of attack: the cooling-off period.

Newly added withdrawal addresses have a mandatory cooling-off period of 24 to 48 hours, during which withdrawals to that address are not possible. If the user, while adding a new address, also resets or modifies the Google Authenticator, fund password, or bound phone number, the entire account's withdrawal function will be locked.

This point is worth elaborating on. The typical path of a social engineering attack is that after obtaining account control, the attacker's first move is often to modify binding information or add their own withdrawal address, kicking out the original owner. But this action itself triggers the lock. In other words, even if the attacker has fully taken over the user's account, they cannot immediately transfer the money away, and the user will receive a notification, with a full day to respond.

In scenarios where the attacker already possesses all the user's information, this type of mechanism is the only thing still working.

We also recently launched a security score mechanism, which lists enabled and not-yet-enabled protection items one by one and assigns a score. Its purpose is not the score itself, but to turn the vague thought of "what should I do" into a checklist that can be completed item by item. We recommend users achieve a security score above 80; upon reaching it, they can also claim protection products.

Q4. When users discover their social media account has been stolen, what is the correct order of handling?

Professor Zhou Yajin of BlockSec: For post-compromise handling, the first step should be to determine the scope of risk impact. Confirm whether the problem is limited to the social media account or has further affected: email, phone number, password management tools, wallets, exchange accounts, cloud services, and development environments. If it's mainly social media account compromise, the following order is recommended.

1) Immediately block the attacker's continued access. Change passwords using a trusted device, force logout of other login Sessions, revoke abnormal OAuth and third-party application authorizations, and reconfigure MFA. If the platform supports it, also check recent login devices, login locations, and security setting changes.

2) Check the upstream identity system. Focus on checking whether the bound email, phone number, and primary device have been controlled. Many social media account thefts are actually just the result of an attack, while the real attack entry point may be email compromise, SIM Swap, Browser Session theft, malware, or Credential leakage. If you only change the social account password without addressing the upstream entry point, the attacker may quickly regain control.

3) Control external impact as soon as possible. Publish risk warnings through the official website, other social media accounts, email, community channels, etc., clearly stating: temporarily do not trust links, contract addresses, investment information, transfer requests, or software installation requests sent from the compromised account. For project teams, KOLs, or institutional accounts, this step is especially important. The main losses caused by account compromise may not be the account owner's own assets, but the attacker using their social influence to attack大量 Followers and partners.

4) If wallets or asset credentials may be leaked, prioritize protecting remaining assets. If you suspect Private Key, Seed Phrase, Wallet Session, or other Wallet Credential leakage, create a new secure wallet using a trusted device as soon as possible and transfer assets still under control. Also check and revoke high-risk Token Approvals and other authorizations in the old address.

The overall principle can be summarized as: control risk and protect assets first, then conduct full forensics. But during the loss-mitigation process, also preserve as much as possible: login notifications, emails, SMS, chat records, malicious links, installers, device logs, transaction hashes, attack addresses, and related screenshots. These materials are of great value for subsequent on-chain fund tracing, exchange coordination, and law enforcement investigations.

Gate Security Team: From the exchange side, let us add some suggestions and content: First, after a social account is compromised, the attacker's next step is often to obtain more information and may attempt to take over the user's exchange account, since that usually holds more directly accessible assets. If abnormal on-platform withdrawals or logins have occurred, retain order numbers, timestamps, and screenshots for coordination. After discovering anomalies, contact official customer service immediately to freeze the account, and the account's withdrawal channel will automatically close. Second, promptly modify the account's bound security items, such as password, Google Authenticator, Passkey. These can be done simultaneously with transferring on-chain assets as Professor Zhou mentioned, without conflict.

Second, if it involves security issues within our platform, we recommend users contact customer service immediately. Many coordination requests we receive come days or even weeks after the incident. This time gap is often decisive. Funds move on-chain in minutes; once multi-hop transfers and cross-chain movements are completed, the room for intervention rapidly narrows.

If the material checklist Professor Zhou listed can be organized and synced to the platform at the earliest opportunity, the actual help would be much greater. If abnormal on-platform withdrawals or logins have occurred, please also retain order numbers, timestamps, and screenshots—the security log in the account can directly retrieve these records. The Gate Security Team is on duty 7X24, and the official website also has a dedicated law enforcement request entry for law enforcement agencies to follow formal coordination procedures.

Another often overlooked point: this is a high-incidence period for secondary scams, so users must be extra careful. After being stolen from, users seek help on social platforms, and immediately various "asset recovery services" approach them, exploiting their vulnerable psychological state, claiming they can help get the money back and charging a service fee upfront. Such scams are numerous. Users should calm down at this point and choose reliable security firms to work with.

Some impersonators even disguise themselves as official exchange coordination personnel. So be sure to contact customer service only through official channels, and to verify whether the other party is official, return to the official verification channel mentioned earlier.

Q5. How do insider attacks differ from external attacks? How should users guard against insider attacks?

Professor Zhou Yajin of BlockSec: The biggest difference between insider attacks and traditional external attacks is that the attacker has more thorough background information on the victim and a higher initial level of trust.

Traditional identity security systems mainly solve: how to prove "the user is who they claim to be." Therefore we use passwords, SMS verification

Safety
Gate.io
Welcome to Join Odaily Official Community