Gate and BlockSec map out social-engineering threats, account takeovers and exchange-side defenses
Gate and blockchain security firm BlockSec used the first installment of Gate Security Classroom to break down one of crypto’s most common loss vectors: social engineering. The discussion focused on account theft, phishing, identity impersonation and insider-style abuse, arguing that attackers often do not need to break blockchains, smart contracts or cryptography. Instead, they exploit trust, hijack communication channels, or pressure victims into signing transactions, changing payment addresses, installing malware or sending funds.
BlockSec co-founder and Chinese University of Hong Kong associate professor Zhou Yajin outlined common attack paths, including social-media account takeovers, SIM-swap-driven Telegram fraud, long-term relationship building before fake investment pitches, and malware delivered through Web3 job interviews or business outreach. Gate’s security team said these patterns closely match what it sees in support tickets and investigations, adding that high-frequency cases often involve ordinary users rather than headline-making celebrity hacks.
The piece also details practical defenses: cross-channel verification for token announcements and payment changes, strict separation between account identity and message authenticity, 24- to 48-hour cooling-off periods for new withdrawal addresses, anti-phishing codes, Passkey support, Gate Ukey, dynamic withdrawal checks, security-score guidance, and faster incident reporting for fund tracing and law-enforcement coordination. Both sides stressed the same point: once an attacker controls a trusted channel, users should stop responding inside that channel and verify through an independent one.