The exchange wasn’t hacked, but your coins are just gone.
Gate users lost $1.7 million. Face, SMS, email, and Google Authenticator were all verified successfully, yet the platform says there’s no vulnerability. The attacker doesn’t need to break into the platform—he only needs to prove, “He is you.”
$23.76 million, in 15 minutes using a single key to completely empty it out.
The Oracle signing key of Ostium was leaked. The attacker submitted forged prices with legitimate signatures. Ten transactions cycled opening and closing positions, and the treasury was emptied. It’s not a contract vulnerability—everything passed verification; the trust source itself was compromised.
North Korea’s Lazarus changed two of Kelp DAO’s validator nodes. It DDoS’d the rest, so the system could only trust the controlled “insider” — forged messages went straight through, and 116,500 rsETH was unlocked and transferred out.
Not a code vulnerability, not a key leak. The issue came from a “convenience” configuration choice: 1/1 DVN single-node validation. LayerZero suggested switching to multi-node, but nobody listened.
He has all contract code, deployment privileges, multi-sig keys, and server root access.
Three months later, an identical competing product appears on-chain.
How did the code get transferred? Can you prevent it?
👇 4 images that explain the code theft prevention in a resignation scenario—after you swipe through, you’ll want to immediately check your company’s access permissions.
DM me for a free resignation scenario security assessment.