@Gate_zh You keep saying "100% compensation if the platform is responsible," but you're pushing all the blame onto the users and even implying "honey traps" and "people who get too close." Money was transferred from your platform, and fake information was allowed to pass the verification process. This can't be simply dismissed as "user information leakage." Stop with the PR rhetoric! Immediately send the original materials for independent analysis and hand over complete evidence to the police. Users have lost real money on the platform; what they want is the truth and accountability.
@Gate_zh Sure, I'd love to see them go to court one day. It's really annoying to have court hearings on Twitter all the time. The "owners" are clearly not just a few people, but a large team.
@Gate_zh Gate responded that the root cause was a "serious leak of user personal information," but how could attackers accurately obtain registration information and transaction records, yet target only this one account? Is Gate's internal data protection truly sound, or is it an attempt to shirk responsibility for its review process?
@Gate_zh Even if the person in charge can withdraw the funds, your exchange should take responsibility, instead of just shirking it here. A major exchange that's been around for 13 years has absolutely no sense of responsibility.
@Gate_zh I have a question. Why did you just happen to choose that unused Alipay account for verification? Did you know that this customer had two Alipay accounts linked to their real name? Another question: why did you choose Alipay's screen recording function when there are so many apps that require real-name authentication, instead of Douyin or WeChat? It doesn't make sense.
@Gate_zh Gate denies any insider involvement, stating there were no unusual query records. However, the attackers possessed far more details than a typical data breach. Can simply stating "this is the only case" dispel all users' doubts?
@Gate_zh Wow, is this a huge undertaking? Will those who participated in the open beta be sent in? What are the rules and restrictions? I'm really looking forward to this open beta.
@Gate_zh It's the same old story, the same old formula. The two-faced behavior is still there. It shows that everyone felt confident locking their money in Gate after the last IPO. Gate's response implies that the victim was set up or had their information leaked by someone who got too close. This is incredibly hurtful for a user who lost a huge amount of money. Don't speculate without evidence. Can you please explain your own review loopholes first?
@Gate_zh 1. The police need the internal records of this fake document approval process, not the external network attack and defense test; only by retrieving the backend records can the truth be revealed. 2. Conducting the test yourself only proves the external network defense, not whether there are vulnerabilities in the manual review process. 3. The police classifying it as a hacking case only means the hacker is guilty, not that the platform's manual review process is without responsibility; these two things should not be confused.
@Gate_zh Why does Gate need records from 7 years ago? Can Alipay be found? Gate claims the Alipay information didn't come from the platform, but the hacker precisely selected the victim's idle account for screen recording.
@Gate_zh Gate claims to have key information on the flow of funds, but refuses to disclose it due to its "sensitive" nature. How can the victims and the public know if you are truly making every effort to recover the funds? Where is the transparency?
@Gate_zh While Gate claims to be "focused on recovering funds," its response implies that victims may have fallen victim to a "honey trap." Is this helping users, or is it causing secondary harm to victims online?
@Gate_zh Gate's long response is very informative, but it doesn't address any of the core issues directly: How did the fake materials pass the review? Was there an inside job? When will an independent investigation be conducted? Users want answers, not a long PR article.
@Gate_zh After all this fuss, I just want to ask, is it possible to use an ID card (which almost everyone leaks) to generate a fake handheld video with AI, pass the authentication of Gate or other CEXs, and ultimately achieve the goal of modifying all the information and withdrawing the money?
@Gate_zh That's too euphemistic. To put it bluntly: either you stupidly leaked your personal information, or you and others are staging this whole thing to extort the exchange.
@Gate_zh Cryptocurrency cases are all prosecuted as illegal acquisition of computer data because in China, cryptocurrencies are considered computer data.
@Gate_zh You mean you just happened to request an Alipay record from 7 years ago, and then the victim's alternate account happened to have a record from 7 years ago, and then, coincidentally, the attacker could log into his alternate account again? 🌚
@Gate_zh The familiar garbage PR statement. I believe any user can see through your disgusting facade. May you go bankrupt soon! May everyone go to jail!
@Gate_zh This is so damn sincere! Who the hell wants to read all this nonsense? Just pull it out from the backend and stop wasting all this time treating users like idiots.
@Gate_zh's data-saving version:
It's impossible for it to be an exchange vulnerability. If there were a vulnerability or an inside job, you wouldn't be the only one who lost money.
There are only two possibilities:
1. You, an idiot, orchestrated this yourself.
2. You were forced to transfer the money.
You didn't check your phone and were still logged into the exchange app during the withdrawal suspension period.
Support without compensation.
@Gate_zh Let me summarize all that nonsense:
Gate:
1: This case is an isolated incident; who knows who will be next?
2: Urging users to report the case to the police as soon as possible to track down the hackers. Is it really that easy to report encrypted crimes in China now?
3: Who checks the messages in the Gate app every day? A text message shows "Beijing Damen Interactive Technology"? Who knows that's Gate?
4: It's still the same old story; old habits die hard. Users who engage in deceptive practices are being scammed, cheated, and kidnapped.
@Gate_zh Go bankrupt! It's ridiculous that Alipay allows cryptocurrency withdrawals, and you guys can even link your accounts to Alipay. I'm speechless.
@Gate_zh This is utterly shameless! Still spouting nonsense about doing everything possible to recover funds and mitigate losses. Compensation should be paid where the money was lost. Your responsibility is to protect user assets when they are not in the user's possession. Your fundamental excuse is blaming the user for leaking the information and not reading your emails. Is there any other way to justify this shamelessness?
@Gate_zh Speaking of technical issues, I can't help but laugh. Last time I bought Korean stocks, I couldn't sell them even with a single click. Can you believe a product that's only been online for about two days?
@Gate_zh I remember you saying it was orchestrated by someone else or someone close to them, and now that others say there's a mole on your platform, you're going to pursue legal action? Looks like your double standards are pretty impressive. You disregard the law, using it when you need to and discarding it when you don't. What a piece of junk platform.
@Gate_zh A little information leak and funds were withdrawn. 170 WU was transferred away in just a few days. Who would dare use your exchange after this? Real-name verification on exchanges is probably useless now.
@Gate_zh So you mean: put the money in the platform, and you keep the profits and traffic;
if there's a problem, just tell the users "it's not a system failure, it has nothing to do with the platform"? Then what's the point of users choosing an exchange?
@Gate_zh Shouldn't you address each and every user question individually to resolve public concerns? The review process is likely flawed and lacks rigor.
@btcmyself@Gate_zh This analogy contains a flaw in legal logic: The criminal liability of third-party hackers does not absolve asset platforms of their civil obligation to conduct due diligence. Platforms have an obligation to identify forged documents and verify identity consistency. In this case, the attackers altered materials to pass manual verification and change account bindings, not to crack the user's original verification. Investigating the hackers and investigating the platform's verification errors are not contradictory. We expect responsibility to be determined through verification logs and third-party assessments.
@btcmyself@Gate_zh Banks that process transactions despite verifying obvious forged documents are also liable for civil damages; this is a consensus based on existing judicial precedents. Even if external information leaks occur, centralized exchanges, as asset custodians, rely on manual verification as the last line of defense against risk and cannot use external risks as an excuse for failing to fulfill their verification obligations.
@btcmyself@Gate_zh 2. Information leakage is only the source problem. The platform's manual verification is the legal last line of defense. The law has never stipulated that upstream information leakage can exempt an institution from the obligation to verify the authenticity of materials.
@btcmyself@Gate_zh 3. In this case, the user's original email address, SMS messages, and Google verification were not compromised. The attacker did not steal passwords to log in, but rather used fake materials to manually change the account binding, which is completely different from ordinary account theft scenarios.
@btcmyself@Gate_zh 4. Criminal liability and civil liability are two separate legal systems. Pursuing the hacker does not mean that the platform can skip substantive identity verification. There is no choice between the two.
@btcmyself@Gate_zh 5. Compliance review is not just about receiving materials, but also includes the obligation to identify fake documents and verify identity information. Simply going through the process of review does not equate to fulfilling prudent duties.
@btcmyself@Gate_zh 6. If user data is leaked, but the submitted materials have many obvious flaws, and the reviewer still approves them, this itself constitutes a failure to fulfill risk control responsibilities.
@btcmyself@Gate_zh 7. The existence of hackers cannot be used to cover up process vulnerabilities. The risk control design of all asset custody platforms is inherently designed to deal with external scenarios such as user information leakage.
@btcmyself@Gate_zh 8. Distinguish between a key fact: it is two different things for a hacker to obtain fragmented information and for a hacker to use fake credentials to deceive the platform's review. The decision to do the latter is in the hands of the platform.
@btcmyself@Gate_zh 9. Industry regulators require exchanges to implement substantive liveness verification. Meeting the requirements on paper does not equate to meeting compliance requirements, and failure to verify will result in corresponding consequences.
@btcmyself@Gate_zh 10. The most direct way to prove one's innocence is to disclose the background review records and accept third-party document verification, rather than using an unequal analogy with banks to defend oneself.
@yicq137@Gate_zh The exchange itself fulfilled its due diligence obligations. It's like a company representative using a forged official seal for transfers; the bank verifies the seal before issuing the loan. They can't possibly authenticate the seal itself. If problems arise with the funds, it's the person who forged the seal's responsibility, not the bank.
@yicq137@Gate_zh If a hacker steals everything from you and withdraws it from an exchange, the exchange bears no responsibility. Both criminal and civil liability rests with the hacker. There are so many real-world cases; do some research. So many people forge official seals and forge legal person or financial seals for use in banks, buying and selling houses—the banks aren't liable. Whoever forges them is responsible.
@yicq137@Gate_zh You're right. First, you need to prove that the bank verified and confirmed it was counterfeit. The bank is only liable if it knew it was counterfeit and still processed the transaction. Furthermore, the bank's role is verification, not identification. The bank won't cover every instance of counterfeiting; completing the verification process fulfills its obligations.
@yicq137@Gate_zh These organizations don't authenticate the materials before processing applications. If that were the case, you'd have to verify the legality of their money before accepting payment, and they'd have to verify the authenticity of all the documents they submit before processing their applications. You can imagine how that would work.
@yicq137@Gate_zh A police report has been filed and accepted. Follow the police's investigation and what they need. Ignoring the police's most authoritative and important method, knowing that the police investigation requires certain information that cannot be disclosed, only disrupts the public. Follow the police investigation results first; further steps can be taken if there are any objections.
@yicq137@Gate_zh What is a fake certificate? How do you determine if a certificate is fake? Is it the platform's responsibility if someone uses a fake certificate to conduct business? If you use a fake certificate, is it entirely the platform's problem?
@yicq137@Gate_zh Victims often initially shift all blame, claiming no responsibility, and may even conceal their mistakes, misleading the public and the police. Now, the platform is bypassing this and communicating with the police to filter out instances of user wrongdoing and concealment of such information.
@zopytarin@Zl6832410@Gate_zh If that's the case, then the other party also stole the time and amount of his first OTC transaction? I ask you, who here can accurately remember the amount and time of their first deposit?
@cfg014412874380@SuiFengR1@Gate_zh In most cases, you wouldn't even look at it. I also have an Alipay account, used for C2C transactions, and I even keep that Alipay account on another iPhone, rarely using it and never looking at it.
original · zh
@cfg014412874380 @SuiFengR1 @Gate_zh 大部分情况下,你也不会看。我也有一个支付宝,是用于C to C的,甚至那个支付宝我就放在另外一个iPhone,平时不用,根本不看
@Zz1Q84@Gate_zh You're such an idiot. Would Alipay record recharges or transactions for Gate? Only a god could accurately determine that these transactions are from Gate.