GateHub Hack
What happened
GateHub's 2019 investigation found that valid customer access tokens had been used to access 18,473 encrypted accounts. The exposed data included encrypted XRP Ledger wallet secrets. GateHub believed the tokens came from unauthorized database access and worked with exchanges to freeze stolen funds.
Compromised access tokens exposed encrypted wallet data. GateHub did not establish publicly how the attacker first obtained the tokens or decrypted the wallet secrets.
How it happened
- The attacker obtained valid customer access tokens, according to GateHub's investigation.
- Those tokens enabled API requests for encrypted account information, including wallet secrets.
- GateHub disabled all access tokens to block further access and began re-encrypting sensitive data with new keys.
- Exchanges and law enforcement were contacted. GateHub's final statement did not establish how much customers would recover.
Protocol details
Evidence
- report Report gatehub.net
- report Report cointelegraph.com
- analysis DeFiLlama defillama.com
- analysis GateHub Investigation - Final Statement gatehub.net
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.