Gate Hack

Reported loss Not disclosed
Bitcoin Ethereum
Supply Chain Attack

What happened

In November 2018 attackers compromised StatCounter, a web analytics service embedded on gate.io, and used it to steal Bitcoin from gate.io users. ESET found that from 3 November the legitimate counter.js script served by StatCounter carried injected code. On most sites it did nothing, but when a visitor opened gate.io's Bitcoin withdrawal page it loaded a second script that swapped the withdrawal address for one controlled by the attackers.

ESET discovered the compromise on 6 November and alerted both companies. Gate.io stopped using StatCounter the same day and said users' funds were safe, and StatCounter removed the malicious code a few hours later, also on 6 November. The amount stolen is unknown: the attacker server generated a fresh Bitcoin address for each victim, so researchers could not total the theft or count victims.

How it happened

  1. The attackers gained write access to StatCounter's infrastructure and inserted packed malicious code into the middle of its legitimate counter.js script, which StatCounter says is used by over 2 million sites.
  2. The injected code checked the page URL and only activated on paths containing myaccount/withdraw/BTC, gate.io's Bitcoin withdrawal page.
  3. On a match it fetched a second-stage script from the look-alike domain statconuter[.]com.
  4. That script replaced the destination address the user had entered with an attacker-controlled Bitcoin address (a new one per victim) and submitted the withdrawal form, so gate.io processed a legitimate-looking withdrawal to the attacker.

Protocol details

Classification Frontend & Infrastructure
Protocol Type CEX
Protocol links Website @Gate

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.