Gate, a prominent centralized cryptocurrency exchange, has recorded substantial net outflows totaling approximately $251 million over a seven-day period, according to data from DeFiLlama. This significant withdrawal activity comes as the exchange faces heightened scrutiny following an alleged theft of $1.7 million from a customer’s identity-verified account. The incident has cast a spotlight on the exchange’s security protocols, account recovery procedures, and overall customer trust, particularly in a market environment increasingly sensitive to security breaches and regulatory compliance.
Tracking the Outflows: A Snapshot of Market Reaction
Initial reports from a July 11 Wu Blockchain snapshot, referencing DeFiLlama data, indicated Gate registered about $207 million in net outflows within a week, positioning it second among centralized exchanges for weekly capital flight. This figure subsequently widened to approximately $251 million on DeFiLlama’s rolling window dashboard, which continuously updates tracked balances. The platform currently monitors nearly $3.98 billion in assets on Gate. In stark contrast to Gate’s situation, Binance, the world’s largest cryptocurrency exchange, led inflows during the same period, attracting approximately $308 million.
While outflow figures require careful interpretation – as DeFiLlama’s methodology removes token-price movements when calculating changes in tracked balances, meaning outflows can stem from various factors such as customer transfers, internal wallet reorganizations, or regulatory migrations rather than solely incident-linked withdrawals – the timing of Gate’s substantial outflows directly correlated with the public disclosure and escalating controversy surrounding the alleged user theft. This confluence of events suggests a direct impact on customer confidence, prompting users to re-evaluate their asset holdings on the platform.
The Alleged Theft: A Detailed Chronology
The dispute originated with a report from user @jheioff, who publicly claimed that an identity-verified account on Gate had been compromised and subsequently emptied without authorization. Blockchain security firm Bitrace later corroborated parts of the claim, reporting unauthorized withdrawals totaling 49.96 ETH, 746,475 HSK, and 1.565 million USDT. The combined value of these assets at the time of the incident was estimated to be close to $1.7 million, making it a significant loss for an individual user.
A detailed timeline of the alleged security breach reveals a concerning sequence of events. Account security settings on the affected Gate account were reportedly altered between July 4 and July 6. Following these changes, five distinct withdrawals were executed on July 7, effectively draining the account. The customer only discovered the missing funds on July 8 and promptly reported the incident to Gate. This chronology immediately raised questions about the efficacy and timeliness of Gate’s identity verification processes, account recovery procedures, and the alert systems in place for critical security changes. The two-to-three-day window between the security changes and the customer’s discovery proved critical, allowing the alleged perpetrator sufficient time to complete the unauthorized transactions.
Gate’s Official Response and Defense of Security Protocols
In the wake of the incident and the ensuing public scrutiny, Gate issued an official statement denying that the incident resulted from a platform-wide breach. Instead, the exchange provided further details regarding the security change request that preceded the withdrawals, aiming to clarify its internal protocols.
According to Gate’s official communication, the individual who initiated the security change request provided accurate identity information, historical trading records, and an Alipay transaction recording. Furthermore, Gate stated that the applicant’s IP address originated from the same geographical region as the account’s recent activity. The exchange also asserted that it sent both email and SMS alerts to the registered contact details when the application for security changes was submitted. These requests reportedly underwent a two-day review period, followed by an additional 24-hour withdrawal restriction, a standard practice designed to provide users with a window to object to unauthorized changes. Gate emphasized that it received no objection from the customer during either the review or restriction window, which it presented as evidence of its adherence to established security protocols.

Despite these assurances, the customer later challenged the legitimacy of the entire process, suggesting a potential failure in the communication or verification stages from their perspective. Acknowledging the widespread criticism regarding its initial public response, Gate subsequently issued an apology, recognizing that its tone had failed to prioritize the customer’s concerns. This admission highlighted the importance of empathetic and transparent communication, especially during sensitive security incidents that erode user trust.
Following the mounting pressure, Gate announced the formation of a specialized task force comprising its security, compliance, legal, and business teams. This multidisciplinary approach aims to thoroughly investigate the incident, enhance existing security measures, and improve incident response protocols. Concurrently, the company has actively assisted law enforcement agencies with documentation and initiated continuous on-chain monitoring of the withdrawn assets in an effort to trace and potentially recover the funds.
The Trail of Stolen Funds: On-Chain Analysis and Recovery Challenges
The journey of the allegedly stolen assets has been partially traced through on-chain analysis. Bitrace reported that the funds were fragmented across several transactions before eventually consolidating at an address identified as being associated with Newpay, a payment service known for its non-KYC (Know Your Customer) policy. Newpay is reportedly linked to the Xinbi ecosystem, providing investigators with a potential focal point for further examination into the ultimate destination and beneficiaries of the stolen cryptocurrency.
The use of non-KYC services like Newpay presents significant challenges for fund recovery. Such platforms typically do not collect or verify the identity of their users, making it extremely difficult for law enforcement and exchanges to identify the individuals behind suspicious transactions. This lack of traceability often allows bad actors to launder illicit funds with a greater degree of anonymity.
In response to the on-chain findings, Gate has confirmed that it has contacted Tether, the issuer of USDT, and other exchanges that may have received portions of the withdrawn assets. The exchange is seeking cooperation to freeze funds that reach identifiable and regulated platforms. However, the ultimate recovery of the funds remains contingent on a complex interplay of factors, including successful law enforcement action, cross-jurisdictional judicial coordination, and the willingness of third-party services and other exchanges to cooperate. The decentralized and global nature of cryptocurrency often complicates such recovery efforts, requiring extensive collaboration across different legal frameworks and operational jurisdictions.
Broader Market Context and Implications for Centralized Exchanges
Gate’s incident and the subsequent outflows occur within a broader landscape of evolving regulatory scrutiny and shifting user sentiment in the cryptocurrency market. Centralized exchanges, while offering convenience and liquidity, are often seen as single points of failure, making them targets for sophisticated cyberattacks and internal breaches. The alleged theft highlights the critical importance of robust multi-factor authentication, stringent account recovery policies, and continuous monitoring of user activity to detect and prevent unauthorized access.
The market has recently witnessed significant shifts, particularly in Europe, where the implementation of the Markets in Crypto-Assets (MiCA) regulation on July 1 prompted many exchanges to reassess their operations. Binance, for instance, experienced heavy monthly outflows around this deadline as European users either migrated to MiCA-compliant entities or opted for self-custody. Similarly, Bybit progressively restricted its global platform access for European Economic Area residents in anticipation of MiCA. Against this backdrop, Gate’s seven-day outflow, directly linked to a security incident, underscores that customer movement is not solely driven by regulatory changes but also by concerns over account security and withdrawal controls.
While the data records a decline in tracked assets on Gate, it is crucial to reiterate that these outflow figures do not inherently prove a solvency problem for the exchange. Rather, they reflect a significant shift in customer trust and a reaction to a high-profile security incident as the investigation and recovery efforts continue. The incident serves as a stark reminder for all centralized exchanges to continuously enhance their security infrastructure, refine their incident response protocols, and prioritize transparent and empathetic communication with their user base. For users, it reinforces the enduring debate between the convenience of centralized platforms and the enhanced security offered by self-custody solutions, where individuals retain full control over their private keys. The outcome of Gate’s investigation and its ability to recover the stolen funds will be closely watched by the industry, shaping future perceptions of security and accountability within the cryptocurrency ecosystem.















