GateHub Hack

Reported loss $10.0M
Ripple
Compromised access tokens

What happened

GateHub's 2019 investigation found that valid customer access tokens had been used to access 18,473 encrypted accounts. The exposed data included encrypted XRP Ledger wallet secrets. GateHub believed the tokens came from unauthorized database access and worked with exchanges to freeze stolen funds.

Technical root cause

Compromised access tokens exposed encrypted wallet data. GateHub did not establish publicly how the attacker first obtained the tokens or decrypted the wallet secrets.

How it happened

  1. The attacker obtained valid customer access tokens, according to GateHub's investigation.
  2. Those tokens enabled API requests for encrypted account information, including wallet secrets.
  3. GateHub disabled all access tokens to block further access and began re-encrypting sensitive data with new keys.
  4. Exchanges and law enforcement were contacted. GateHub's final statement did not establish how much customers would recover.

Protocol details

Classification CeFi / Access Control
Protocol Type Exploit/Access control
Protocol links Website @GateHub

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.