Gate Hack
What happened
In November 2018 attackers compromised StatCounter, a web analytics service embedded on gate.io, and used it to steal Bitcoin from gate.io users. ESET found that from 3 November the legitimate counter.js script served by StatCounter carried injected code. On most sites it did nothing, but when a visitor opened gate.io's Bitcoin withdrawal page it loaded a second script that swapped the withdrawal address for one controlled by the attackers.
ESET discovered the compromise on 6 November and alerted both companies. Gate.io stopped using StatCounter the same day and said users' funds were safe, and StatCounter removed the malicious code a few hours later, also on 6 November. The amount stolen is unknown: the attacker server generated a fresh Bitcoin address for each victim, so researchers could not total the theft or count victims.
How it happened
- The attackers gained write access to StatCounter's infrastructure and inserted packed malicious code into the middle of its legitimate
counter.jsscript, which StatCounter says is used by over 2 million sites. - The injected code checked the page URL and only activated on paths containing
myaccount/withdraw/BTC, gate.io's Bitcoin withdrawal page. - On a match it fetched a second-stage script from the look-alike domain
statconuter[.]com. - That script replaced the destination address the user had entered with an attacker-controlled Bitcoin address (a new one per victim) and submitted the withdrawal form, so gate.io processed a legitimate-looking withdrawal to the attacker.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.