Skip to content
Yieldo

Gate

$235.0M
Funds stolen
Funds returned
21 Apr 2018
Date of incident
Technique
Private Key Compromised
Classification
Key Compromise
Target type
CEX
Source
No public source link

Gate (then trading as Gate.io, and originally as Bter before its 2017 rebrand) lost an estimated $230–235 million in Bitcoin, Ether, and five other assets on April 21, 2018, after attackers gained control of the private keys securing the exchange's wallets. Unlike most exchange hacks of that era, the breach was never publicly acknowledged by the exchange — it surfaced only in November 2022, when on-chain investigator ZachXBT published a wallet-tracing thread accusing Gate.io of a four-year cover-up (CryptoSlate).

How the attack worked

The publicly documented breakdown of stolen assets — roughly 10,778 BTC, 218,790 ETH, 175,866 ETC, 3.04 million XRP, 99,999,000 DOGE, 11,000 LTC and 3,783 ZEC — points to a wallet-level compromise rather than a smart-contract exploit: someone obtained valid signing authority over the exchange's wallets and moved funds out directly, the same way a legitimate operator would (CoinEdition). That is what the classification Private Key Compromised (Unknown Method) describes: the outcome is well evidenced on-chain, but Gate.io never published a post-mortem, so the initial vector — a phished employee, malware on a signing machine, an insider, or something else — has never been disclosed. This is the defining trait of infrastructure-level custody failures: once keys are in an attacker's hands, the theft is indistinguishable from routine operations until withdrawals actually hit the blockchain.

What happened next

Gate.io neither confirmed nor denied the hack when confronted in 2022; it answered ZachXBT's questions with a general statement about the platform's "built-in mechanisms" against penetration, without addressing the specific allegation (CryptoNews.net). No law-enforcement action, arrest, or attacker identification tied specifically to this incident has been reported, and none of the stolen $230–235 million has been recovered. The funds did not stay dormant forever: in February 2023, analysts flagged the movement of 1,944.72 ETH (about $3.2 million) that had sat untouched for over four and a half years, routed through a chain of addresses before part of it reached MEXC (CryptoSlate). The exchange itself survived: it kept operating under the Gate.io brand for years afterward and rebranded to "Gate" in 2025, today ranking among the larger global exchanges by volume.

What this means

  • A hot-wallet key compromise is invisible from the outside — depositors have no way to detect that an exchange's signing infrastructure has been breached until withdrawals actually move, which is exactly why this hack stayed unconfirmed for over four years.
  • Non-disclosure is a business decision, not a technical constraint: nothing forces a private exchange to publish a post-mortem, and the absence of one here means the true attack vector will likely never be known.
  • Dormant-wallet monitoring works on long timescales — funds untouched for 4.5 years still got flagged the moment they moved, which is the practical reason fully laundering stolen crypto stays hard even years later.
  • The only forward-looking signal available to a depositor is custody architecture disclosed before an incident — cold-storage ratios, multisig thresholds, proof-of-reserves — since after-the-fact statements from the exchange itself, as this case shows, cannot be relied on.

On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.