Gate and BlockSec map out social-engineering threats, account takeovers and exchange-side defenses

Gate and BlockSec map out social-engineering threats, account takeovers and exchange-side defenses

N
News Editor
2026-09-14 10:15:04
Gate and blockchain security firm BlockSec used the first installment of Gate Security Classroom to break down one of crypto’s most common loss vectors: social engineering. The discussion focused on account theft, phishing, identity impersonation and insider-style abuse, arguing that attackers often do not need to break blockchains, smart contracts or cryptography. Instead, they exploit trust, hijack communication channels, or pressure victims into signing transactions, changing payment addresses, installing malware or sending funds. BlockSec co-founder and Chinese University of Hong Kong associate professor Zhou Yajin outlined common attack paths, including social-media account takeovers, SIM-swap-driven Telegram fraud, long-term relationship building before fake investment pitches, and malware delivered through Web3 job interviews or business outreach. Gate’s security team said these patterns closely match what it sees in support tickets and investigations, adding that high-frequency cases often involve ordinary users rather than headline-making celebrity hacks. The piece also details practical defenses: cross-channel verification for token announcements and payment changes, strict separation between account identity and message authenticity, 24- to 48-hour cooling-off periods for new withdrawal addresses, anti-phishing codes, Passkey support, Gate Ukey, dynamic withdrawal checks, security-score guidance, and faster incident reporting for fund tracing and law-enforcement coordination. Both sides stressed the same point: once an attacker controls a trusted channel, users should stop responding inside that channel and verify through an independent one.

Gate and blockchain security company BlockSec used the first edition of Gate Security Classroom to examine a category of crypto attacks that keeps causing losses without relying on sophisticated exploits: account theft, phishing, social engineering, identity impersonation and scams carried out through trusted relationships. The article opens with a simple case. If a business partner messages you on Telegram and says the company payment address has changed, then sends a stamped confirmation letter, what should you do first? Gate’s answer is not to judge whether the screenshot looks real, but to leave that conversation and verify through another channel.

Gate and BlockSec map out social-engineering threats, account takeovers and exchange-side defenses 2

The session brought together BlockSec co-founder and Chinese University of Hong Kong associate professor Zhou Yajin and Gate’s security team. The discussion moves through the mechanics behind high-frequency losses, the difference between on-chain theft and exchange-account compromise, and the controls that still matter once an attacker already has personal information or access to a trusted account.

BlockSec and Gate laid out their security credentials

Zhou is introduced in the piece as an associate professor at the Chinese University of Hong Kong and a co-founder of BlockSec. The article says he has published more than 50 papers in top-tier security conferences and journals, with more than 10,000 citations, and is now exploring ways to rebuild system infrastructure to improve the efficiency and safety of AI agents.

BlockSec was founded in 2021 and focuses on blockchain security and compliance, covering on-chain protection, fund tracing and investigation, and digital-asset compliance. According to the article, the company serves more than 1,000 clients globally, has protected more than $50 billion in on-chain assets, maintains a database of more than 600 million illicit-address labels, and has fully reconstructed a single case involving as much as $1.6 billion.

Gate’s security team says it is responsible for the platform’s account, trading and asset security systems and also handles abnormal-account appeals and investigative assistance requests. Gate, founded in 2013, is described in the article as the first exchange in the industry to launch a 100% proof of reserves, and it says it now serves more than 60 million users worldwide. For the company, the team says, security is not an add-on. It is a basic condition for the business to work at all.

Social engineering attacks target trust rather than blockchain code

Zhou describes the core trait of social engineering this way: the attacker does not directly break the blockchain base layer, smart contracts or cryptographic mechanisms. Instead, the attacker controls identity, controls a communication channel, or abuses an existing trust relationship to induce the victim to transfer funds, sign transactions, grant approvals or install malicious software.

He groups common attacks into several patterns.

  • First, social-media account takeovers. The attacker does not fake the account but takes over the real one, then uses the credibility and reach it built over time to push tokens or phishing links. A real account does not mean the message being sent from it is real.
  • Second, targeted fraud after a communication channel is hijacked. The article cites Cheng v. T-Mobile, disclosed in U.S. federal court filings, as a representative case. In that matter, the attacker allegedly used a SIM swap to seize control of a phone number, then took over a real Telegram account and used an existing bitcoin trading relationship to induce the victim to send 15 BTC by offering to buy at above-market prices. The account was real, the contact was real and the prior relationship was real, but the person issuing the instructions was no longer the original owner.
  • Third, trust-building over months before steering the victim into a fake investment platform. Zhou says attackers can enter a victim’s daily life as a friend, investment adviser, tenant or potential business partner, then spend months or longer building confidence. In this setup, no account theft is required at the start. The attacker becomes a person the victim trusts.
  • Fourth, malware delivery disguised as recruitment or business cooperation. The article points to the GrassCall attack disclosed in 2025, in which attackers used a Web3 online job interview as bait and asked targets to download meeting software that actually carried infostealing malware aimed at browser credentials and crypto wallets. Similar pretexts include claims that a camera is not working or a Zoom plugin needs an update, then pushing the user to run terminal commands.

Gate’s security team says these categories line up closely with what it sees in appeals and investigation support requests. In many of those cases, the attacker never needs to penetrate the exchange itself.

The team says Gate runs AI- and machine-learning-based real-time threat detection, end-to-end encrypted transmission, distributed traffic scrubbing, Anycast and DNSSEC. Social engineering does not defeat those layers directly. It goes through the user. That, the team says, is why some risks can be reduced through platform hardening, while others depend on user recognition, and those user-side failures are often the ones that produce the largest losses.

Many high-frequency cases involve ordinary users, not celebrities

Gate adds two observations from the exchange side.

The first is a frequency illusion. Celebrity account hacks make headlines, but the tickets the exchange receives point to a different pattern: the most frequent victims are ordinary users. A compromised Telegram account may push acquaintances to make a payment, tell a counterparty to switch the receiving address, or impersonate a project team and publish a fake mint address. A single loss may be only a few thousand dollars and may never appear in the media, but the number of such cases is far larger, the team says.

The second is impersonation of exchange support. Attackers pretend to be Gate customer service over email, text message or social-media direct messages, usually citing an abnormal account event, a required verification check or a pending withdrawal. Gate says it offers two tools that can be used immediately.

  • An official verification channel that lets users check whether a domain name or contact email belongs to Gate.
  • An anti-phishing code chosen by the user. Every legitimate Gate email will include it. By contrast, any email that claims to be from Gate but does not carry that code should be treated as fake. The team says the main advantage here is that the mechanism does not depend on a user spotting an extra letter in a sender domain or judging whether the wording sounds official.

Account authenticity and message authenticity must be checked separately

When a celebrity or project account suddenly posts a token contract address, or when a friend’s account appears to have been compromised, Zhou says users should start from a basic rule: an account being real does not make the message itself trustworthy.

Even if information comes from a verified official account, a project account, a celebrity account or a long-time contact, users should not move straight into a high-risk action based on identity alone. He singles out buying newly issued tokens, connecting a wallet, signing on-chain transactions and granting token approvals as actions that need extra caution.

Zhou gives several checks users can make.

  • Cross-channel verification. A single account on X, Telegram, Discord or WeChat should not be the only source. Users should also check the official website, other official social channels, community announcements and trusted third-party information sources. If a project suddenly announces a new token, airdrop or mint while its website and other official channels remain silent, that alone should count as an abnormal signal.
  • Review of on-chain asset and contract status. Zhou says users can look at contract deployment time, the deployer address, liquidity size, holder concentration, visible fund relationships among major addresses, and whether there is a pattern of fast price pumping followed by concentrated selling. He does not say every user needs professional-grade on-chain investigation, but he does say a basic check through trusted block explorers and security tools is a minimum step.
  • Do not rush into an unverified trade. Social engineering often depends on FOMO and urgency. Phrases such as “ending soon,” “limited-time claim,” or “buy now or miss it” are really there to compress the time available for verification. For a new asset that has not been verified, waiting usually beats rushing.

If the case involves a friend, business partner or colleague suddenly requesting a transfer or changing a payment address, Zhou says verification should happen through a second channel that is independent from the original one. If the request came through Telegram, call. If the address change arrived by email, verify it through a previously confirmed contact method. For large transfers, confirm again and send a small test amount first. His key rule is clear: do not let the same channel potentially controlled by the attacker handle both the request and the identity check.

On-chain wallet theft can finish in seconds, exchange withdrawals still pass through gates

Gate says the biggest difference between exchange-account risk and on-chain wallet theft is time.

When a wallet is drained on-chain, a signature and the asset transfer can collapse into a single step and be final within seconds. Inside a centralized trading platform, by contrast, there are more stages between stolen login credentials and funds actually leaving the account. Gate says it designs account security across four stages: login, trading, withdrawal and security settings, each with separate checks.

  • At login, Gate lists password checks, email, SMS, Google Authenticator and IP monitoring. The platform warns users about unusual login locations, and account security logs record login history and key actions for self-inspection.
  • At withdrawal, the fund password is separate from the login state and is not used in everyday sign-ins. Gate says that means an attacker who gets login control is still one credential away from moving funds. It also says withdrawal checks can change dynamically based on environment changes, amount and the account’s overall risk profile, with stricter verification for higher-risk withdrawals.
  • For outbound channels, users can disable paths they do not currently need. The reasoning is direct: one less active route means one less route that can be abused.
  • In security settings, the team highlights a cooling-off mechanism that many users do not know about. A newly added withdrawal address is subject to a mandatory 24- to 48-hour cooling-off period during which withdrawals to that address are blocked. If a user adds a new address while also resetting or changing Google verification, the fund password or the bound phone number, the account’s withdrawal function is locked.

Gate says a common social-engineering path is for the attacker, after gaining control, to change bound information or add a withdrawal address under their control and push out the real owner. Those actions themselves trigger the lock. In practice, the team says, even if an attacker fully takes over the account, the funds cannot be moved immediately, the user receives notice, and there is at least a day to respond. In a scenario where the attacker already has all of the user’s information, Gate calls this type of mechanism the only thing that may still be working.

Gate and BlockSec map out social-engineering threats, account takeovers and exchange-side defenses 3

The exchange also says it recently launched a security score that lists enabled and missing protections item by item and gives the account a rating. The point is not the rating itself, the team says, but turning a vague sense that “I should do something” into a checklist that can be completed one step at a time. Gate recommends users push the score above 80, after which they can also claim protection-related products.

After a social-media account is lost, stop access first and preserve evidence as you go

Zhou says response should begin with scope. Users need to determine whether the incident is limited to a social account or has spread to email, phone numbers, password managers, wallets, exchange accounts, cloud services or development environments.

If the problem is mainly a compromised social account, he recommends this sequence.

  1. Immediately cut off the attacker’s continued access. Use a trusted device to change the password, force logouts on other sessions, revoke abnormal OAuth and third-party app authorizations, and reconfigure MFA. If the platform supports it, also review recent login devices, login locations and any changes to security settings.
  2. Check the upstream identity stack. Bound email accounts, phone numbers and the main device should be reviewed first. Zhou says many social-account takeovers are only the final result, while the true entry point may be email compromise, SIM swap, stolen browser sessions, malware or leaked credentials. If a user changes only the social-account password without fixing the upstream breach, the attacker may quickly regain control.
  3. Contain external damage. Issue warnings through the official website, other social accounts, email and community channels, telling users not to trust links, contract addresses, investment messages, transfer requests or software-installation instructions sent from the compromised account. For project teams, KOLs and institutions, he says this is especially important because the major losses may hit followers and counterparties rather than the account owner.
  4. If wallet credentials may have leaked, protect remaining assets first. If there is reason to believe a private key, seed phrase, wallet session or other wallet credential has been exposed, create a new secure wallet on a trusted device as soon as possible and move still-controlled assets there. High-risk token approvals and other authorizations on the old address should also be reviewed and revoked.

He sums up the approach as control risk and protect assets first, then complete full evidence collection. At the same time, users should preserve login notices, emails, texts, chat logs, malicious links, installers, device logs, transaction hashes, attacker addresses and screenshots because those materials matter for on-chain tracing, exchange cooperation and law-enforcement inquiries.

Gate adds that once a social account is compromised, the attacker’s next move may be to gather more information and then attempt to take over the victim’s exchange account, where assets are more directly accessible. If abnormal withdrawals or abnormal logins have already happened on the platform, users should retain order numbers, timestamps and screenshots, then contact official support immediately to freeze the account. Gate says the outbound channel will be closed automatically. At the same time, users can change security items such as passwords, Google Authenticator and Passkey. Those steps do not conflict with moving on-chain assets to safety.

The exchange says many investigation-support requests arrive days or even weeks after the incident. By then, funds may already have moved through multiple hops and across chains, sharply reducing the room to intervene. Gate says its security team is staffed 24/7 and that its website includes a dedicated law-enforcement request portal for formal cooperation.

The team also warns about a second wave of fraud. Victims often seek help on social platforms after a theft, and that quickly attracts “asset recovery services” claiming they can get the money back in exchange for an upfront fee. Gate says these scams are common and that some impersonators even present themselves as official exchange investigators. Users should contact support only through official channels and verify identities using the official verification method mentioned earlier.

Insider-style abuse weakens traditional identity checks

Zhou says the main difference between insider-style abuse and external attacks is that the attacker starts with richer background information and a higher level of trust.

Traditional identity systems are built to answer one question: how do we prove the user is the user? That is why they rely on passwords, text-message codes, authenticators, device recognition, facial verification, identity documents and KYC. In an insider scenario, though, the attacker may already know or have long-term access to the victim’s usual email account, phone number, identity documents, date of birth and password habits. Many of those data points are exactly what account-recovery and customer-service processes use for identity verification. For someone with sustained exposure to the victim’s life and devices, the effectiveness of some standard authentication methods can drop sharply.

On-chain behavior can look different as well. External attackers often want fast transfers and lower freezing risk, so funds may be consolidated, bridged, moved through multiple hops and sent into mixers quickly. Insider abuse may stretch out over longer periods. Because the attacker understands the victim’s asset size and habits, theft may show up as smaller amounts, repeated more times, over a longer span. The money flow may not display the more obvious patterns often associated with hacker laundering.

That is why, Zhou argues, insider risk cannot be handled by simply choosing people to trust. It requires least privilege and separation of powers. For individuals, he recommends separating day-to-day wallets from long-term asset wallets and using separate devices for digital-asset operations. For institutions, he points to a fuller system spanning initiation, approval, signing, execution, large-transaction review and abnormal-behavior monitoring.

Gate says this matches what it sees in appeal handling. These cases are difficult because, from the system’s perspective, every step may look legitimate: the usual device, the home IP address, the right password, and verification codes delivered to the real user’s phone. Technical traces all point to “the user did it,” leaving the platform with limited room to judge and making it hard for the user to prove otherwise later.

To raise protection in such situations, Gate recommends Passkey. The team says Passkey is a pair of keys bound to the user’s device and verified with biometrics. It highlights two advantages. One, Passkey is phishing-resistant because it is bound to the domain name, so a fake site that looks identical to the official one still cannot trigger a valid Passkey prompt. Two, losing a device does not automatically mean losing the account. Even if someone gets a phone that is already unlocked, they still cannot pass the check without the user’s biometric data.

For stronger physical isolation, Gate points to Gate Ukey, a hardware security key that can be used for login, withdrawals and changes to security settings. The team’s argument is simple: information can be known, but a physical key must be physically possessed. An attacker may know a user’s birthday, ID number, common passwords and email account, and may even get the phone, but without the Gate Ukey the attacker still cannot complete verification.

Gate again stresses the role of the cooling-off period in insider scenarios. Insider abuse often still requires changing bound information or adding a withdrawal address, which triggers a 24-hour withdrawal lock and sends a notice to the user. That forced pause creates a chance to catch the attack. The team also repeats several account-hardening suggestions: keep the security score above 80, separate the fund password from the login password, lower daily withdrawal limits proactively, and disable unused outbound methods.

In Web3, identity, permissions and assets sit closer together

Zhou says Web3 is especially exposed to social engineering because the distance between identity, permissions and assets is very short.

In the traditional internet environment, a stolen social-media account usually leads first to impersonation, information exposure or unauthorized content posting. In Web3, once a Telegram, X or Discord account is taken over, it can quickly be used to post malicious contract addresses, ask for signatures or induce direct asset transfers.

Another factor is the strong irreversibility of blockchain transactions. If a user produces a cryptographically valid signature and the transaction is confirmed on-chain, there is usually no direct cancellation path like the one users may expect in traditional payment systems. So the attacker does not necessarily need to crack the blockchain or the private key. If the attacker can socially engineer the user into making one “valid” signature or transfer, the theft can be completed. In Zhou’s framing, that means Web3 security boundaries cannot stop at the smart contract. They must also cover wallets, front ends, social accounts, identity systems, devices, transaction signing, asset permissions and user behavior.

Gate and BlockSec map out social-engineering threats, account takeovers and exchange-side defenses 4

Gate approaches the same issue from a different angle. The team says Web3 and the blockchain industry face an impossible triangle in which decentralization, security and speed cannot all be maximized at once. In traditional finance, a person who gets hold of someone’s identity information still has to get through manual bank checks, transfer delays, manual review of abnormal transactions, dispute handling and chargeback-style processes. Those layers slow things down, but they also create time to correct mistakes. On-chain, one signature can settle things within seconds. Speed and decentralization are high, but security cannot be identical to that of traditional finance.

That, Gate says, is one reason centralized exchanges retain some of the security characteristics of traditional centralized finance. The article repeats several exchange controls here: a 24- to 48-hour cooling-off period for new withdrawal addresses, and a 24-hour lock on account withdrawals if a new address is added while Google 2FA, the fund password or the bound phone number is reset or changed. Fund passwords, daily withdrawal limits, cooling-off periods for new addresses and secondary verification for abnormal logins all add friction, the team says, but they exist for one reason only: keeping user assets safe.

The article also includes Gate’s latest proof-of-reserves figures. The company says it was the first major platform in the industry to commit to a 100% reserve ratio, using Merkle tree technology together with zk-SNARK zero-knowledge proofs. Its latest audit showed total reserves of $8.215 billion and a reserve ratio of 127%. The audit date listed is Aug. 19, 2026, and the audit was completed by third-party firm HACKEN. Gate says the implementation code has been open-sourced on GitHub and any user can download the verification program to check whether their balance is included in the proof of reserves.

Tracing funds does not guarantee recovery, but it still shapes the chance of intervention

On the question of whether fund tracing still matters after assets have already been transferred out, Zhou gives a clear yes. Social engineering explains how the attacker obtained the assets. On-chain investigation answers where those assets went after leaving the victim address.

Because blockchain fund flows are public and verifiable, investigators can keep tracking how stolen assets are consolidated, whether they move through mixers, when they are deposited into exchanges, and how different attacker addresses may relate to one another. Investigators can also look for common funding sources, shared gas sources, matching paths and similar laundering patterns, then organize those findings for law-enforcement follow-up. Zhou says this is one of the central problems addressed by on-chain investigation tools such as BlockSec MetaSleuth.

He draws a line, however, between traceability and recovery. Funds being traceable does not mean they will definitely be recovered. Actual freezes and recoveries often require rapid coordination among centralized exchanges, stablecoin issuers, security companies and law-enforcement agencies. In major theft cases, response time matters. The sooner an abnormality is detected, the sooner preliminary tracing is done, and the sooner relevant parties are contacted, the greater the chance of opening an intervention window before the attacker moves the funds further.

Gate says the exchange sits directly inside that cooperation chain. If stolen funds flow into the platform, the company says it can intercept them using risk labels and abnormal-behavior detection. The article says Gate runs a real-time risk assessment system based on machine learning that judges withdrawal requests, adjusts limits dynamically, and monitors and intercepts abnormal trading activity based on account behavior and risk level.

The team adds an important legal boundary. Funds may keep moving on-chain, but once an attacker tries to convert them into fiat or move them into another trading system, they will likely pass through a centralized node and leave an identity trace. Still, if a freeze would affect another user’s lawful rights, the platform needs a formal legal basis or an official law-enforcement cooperation request. It cannot freeze another user’s assets on the strength of a one-sided claim alone.

Gate says users can raise the odds of successful intervention by doing three things.

  1. Preserve evidence quickly and file a report. Screenshots, transaction hashes and chat records matter, and users should contact law enforcement or platform support immediately. Gate says its website includes a dedicated law-enforcement request entry point for this process.
  2. Send materials right away, including transaction hashes, timeline details and counterparty addresses. The exchange says the transaction hash and attacker address are the two most important items for getting on-chain tracing started.
  3. Do not wait. Gate says a significant share of investigation-support requests arrive several days after the incident. Funds move on-chain by the minute, while human response often moves by the day, and that time gap is one of the attacker’s biggest advantages.

The team closes this part with one more point: blockchain data is permanent. An attacker may choose not to touch the funds today, but if those funds are ever monetized, they must pass through some identifiable node. Breakthroughs in many cases, the article notes, happen months or even years after the original theft.

Hardening advice starts with separation: identity, devices, assets and verification channels

In the final section, Zhou says the goal of social-engineering defense should not be to guarantee that users will never be deceived. A more realistic goal is to use technical design and process design to reduce the maximum damage a single identity compromise, device compromise or human judgment error can cause.

He then lists six concrete measures.

  1. Identity separation. Core email accounts should not be used to register low-trust third-party services. Important accounts should use different passwords and enable MFA. High-value accounts can also use hardware security keys to reduce the risks tied to SMS codes and single-device authentication.
  2. Device separation. Devices used to manage large assets should be separated from everyday browsing, social communication and file downloads. Wallets used for daily activity should also be separated from wallets holding long-term large balances.
  3. Asset and permission separation. A single address, a single account or a single person should not hold all assets and all operating authority at once. Institutional users can build layered defense with multisig, MPC and tiered approvals.
  4. Verification-channel separation. High-risk operations such as large transfers, receiving-address changes and permission changes should be confirmed through a second, independent channel. The same channel should not be used for both the operational request and identity confirmation.
  5. Extra controls for abnormal behavior. Even after identity checks pass, obviously unusual behavior should trigger additional review, such as transfers far above historical levels, large operations at abnormal times, or the first transfer to an unfamiliar address.
  6. Isolation for recruiting, investment and business interactions. This point is especially aimed at Web3 workers. Unknown recruiters, investors, project teams or potential business partners may send meeting software or installation packages. Those should not be run directly on a main device that stores real wallets, browser sessions, SSH keys, API keys or production credentials. Where possible, use a separate device, a virtual machine or another isolated environment.

Zhou highlights several pretexts users should treat with suspicion: “your camera is not working, run this command,” “please update the Zoom plugin,” “this is our internal interview software,” “clone this project and run it first,” and “connect your wallet so we can test the product.” For Web3 users, he says, job offers, investment opportunities and business cooperation all need to be included in the threat model.

Gate brings the discussion back to the platform’s own controls. The team recommends using the new security-score product as a starting point. It lays out protections one by one, including fund passwords, two-factor authentication, anti-phishing codes, withdrawal whitelists, daily withdrawal limits and outbound-method management. Reaching a score above 80, the team says, means the most basic gates are in place.

Gate also points to a risk outside the platform that users often miss: public information left across the internet. Using a real name at conferences, posting asset screenshots to private social feeds, or binding a main on-chain address to ENS or a social account may each look harmless in isolation. Combined, though, they give an attacker a richer profile. If someone can learn how much money a target has, what the target is called, where the target often goes and who the target knows, targeted scams, long-term trust building and identity impersonation become cheaper to execute and more likely to succeed.

The exchange adds that security should not be a one-way demand placed on users while the platform remains opaque. Gate says it runs a long-term security bug bounty program and accepts issue reports through sec@gate.com, the support ticket system or the HackenProof platform. Its proof of reserves is also audited by a third party and open-sourced so users can verify it themselves.

The article ends where it began. If a business partner sends a new payment address on Telegram and includes a stamped screenshot, the right move is not to spend time judging the screenshot. The right move is to close the chat and contact the person through another channel. Social engineering is hard not because it defeats code at a high technical level, but because it attacks the user’s judgment in the moment. In that sense, the first line of defense in crypto is still the ability to stop the most common and most damaging attacks before they turn trust into a transaction.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.