5/10
IV. Gate provided misleading information to the police, disrupting the investigation
1. Gate told the police that "between July 4th and 8th, the platform sent verification codes to my phone number and email address. After all verifications were successful, the user reset the security settings themselves." This statement would mislead the police into believing that my email address, phone number, or device had been compromised.
However, the actual security logs show that my email address, phone number, login password, funds password, and Google Authenticator were all subsequently modified or reset. The attacker verified the security settings that had been changed, not my original email address, phone number, and Authenticator.
2. Gate also claimed that "on July 6th, when the user changed their login password, funds password, and Google Authenticator, they verified both the email verification code and the funds password." However, the email address and funds password had already been changed by the attacker at that time, and these verifications could not prove that the account holder had performed the operation. Gate's statement deliberately obscures the distinction between "original security settings" and "security settings reset by the attacker," directing the police investigation towards "user email or device infection," thus concealing the real issue: Gate's manual verification allows attackers to bypass the user's original authentication, reset all security settings, and transfer all account assets. Gate cannot bypass my original security verification while simultaneously shifting responsibility to the user. 3. My Mac computer contains Gate's access key; I can log in simply by pressing my Mac keyboard fingerprint, and there are no abnormal pop-up alerts after logging in. Gate's initial accusations that I logged in using an old device and that my old device was stolen are baseless. All my old devices are with me and in good condition. Having used Web3 for so many years, it's common sense that I wouldn't sell or discard old devices. Gate is disrupting the correct investigative direction, delaying the attacker's investigation, and obstructing judicial fairness.
@jheioff I think I understand now. To evade regulation, they didn't use the official facial recognition channel. As a result, their own facial recognition channel, which uses a combination of manual and machine recognition, was "reasonably" bypassed.
Why is it considered reasonable? Because this recognition technology is not cheap, and to save money, they could simply use AI recognition, which just tells you a so-called percentage.
And internally, the redundancy in this percentage is probably quite extensive.
7/10
VI. Gate claims to be cooperating with the police, but where are the leads?
Gate has repeatedly stated publicly that it is "fully cooperating with the police" and "has obtained a large amount of information." However, as far as I know, Gate has not yet provided the police with any information that could effectively pinpoint the attackers.
If you truly possess a large amount of information, why not immediately and completely submit it to the police to assist in apprehending the attackers? True cooperation is not about releasing public relations statements, but about handing over the evidence you have to the police.
Is this delay in providing information an attempt to protect the attackers?
8/10
VII. Gate, please conduct an authoritative verification of the risk control materials immediately.
Gate, please provide a direct answer regarding the verification time; this is the most important point. Don't try to explain further. Please have Gate submit the original materials submitted by the attacker—the ID card held in hand, the live face video, and the complete review records—to a qualified independent and authoritative institution for verification.
My stance is very clear:
If the verification proves the ID card held in hand is genuine and valid, and the person in the live face video is indeed me, I will no longer pursue legal action against Gate and will issue a public apology.
Conversely, if the verification confirms the ID card is forged, the live face is not mine, and the withdrawal was not made by me, this is sufficient proof that the attacker used false materials to breach Gate's verification and risk control system.
Gate has publicly promised: "If it is the platform's responsibility for verification, 100% compensation will be provided." If the verification confirms that fake materials and a non-person's live face passed the platform's verification, please have Gate immediately fulfill its promise, assume responsibility, and provide 100% compensation to users for their losses. The beastly Gate must stop creating controversy and insinuating against users.
On October 10th, Gate.cn didn't directly respond to when they would implement "ID card hand-held material + liveness video verification." Instead, they kept throwing out claims like "honey trap," "insider theft," and "two Alipay accounts stolen," implying victimized users and diverting public attention. Gate.cn is a master of lying, shirking responsibility, blaming users, saying one thing and doing another, lacking accountability, contradicting themselves, and delaying action. Gate.cn is a pile of risk control garbage disguised as an exchange: their pre-incident checks are practically non-existent, and afterward they turn a deaf ear, refusing to submit evidence or admit responsibility, only capable of spreading rumors, shifting blame, and confusing the public. Money was transferred from their platform using fake information and by unregistered individuals, yet they turn around and blame the users—both incompetent and shameless. Their so-called "security" is a joke, and their so-called "100% compensation" is utter nonsense. Gate.cn doesn't deserve to talk about risk control; they only deserve to be nailed to the pillar of shame in the cryptocurrency world!