Open app

NexFlow › Is Gate safe

Is Gate safe? The oldest exchange in the set — hack survivor, PoR pioneer

Gate.io has the longest timeline in this entire corpus: founded April 2013 as Bter.com — before Ethereum existed — robbed of ~7,170 BTC in February 2015, reborn as Gate.io in 2017, and then, in May 2020, the first mainstream exchange ever to publish an audited 100% proof of reserves (Armanino, 104% collateralization). Twelve years is enough runway for both a worst-case and a best-case to be fully documented — including a ~$230M allegation it has never formally acknowledged. No page in this family has more history to weigh.

Updated September 28, 2026 · By the NexFlow editorial desk · Sources linked throughout; vendor claims labeled.

What Gate is

Gate (Gate.io, rebranded Gate.com in 2025) is among the oldest continuously operating crypto exchanges — founded in China as Bter.com in April 2013, relaunched under its current name in 2017 after China's exchange crackdown, now reporting 50M+ users and the widest asset menu in the industry (thousands of listed tokens — the long-tail listing machine before MEXC made it a strategy). Custody shape is standard CEX; what distinguishes Gate is tenure: it has operated through every crypto era including ones that killed most of its contemporaries.

February 2015: the Bter hack

The prehistory matters because the venue chose to build on it rather than hide it. In February 2015, operating as Bter.com, the exchange disclosed the theft of approximately 7,170 BTC (~$1.75M then) from what it described as a cold wallet — a catastrophic sum in 2015 terms, in the same era that produced Mt. Gox. The platform temporarily shut down and committed to repaying users, which it did through staged repayment funded by platform revenue — the make-whole mechanism of the era, years before SAFU-style insurance funds existed as a named instrument.

The honest reading: a 2015 cold-wallet breach is a genuine black mark — "cold" storage that could be robbed is the exact failure the architecture exists to prevent. It is also eleven-plus years ago, under a different company name, in an industry that had not yet invented most of the controls now standard. What the incident produced in Gate is the more relevant fact: the exchange that was robbed in 2015 spent the following decade becoming the industry's earliest and loudest prover of reserves — the trauma-response theory of exchange safety, documented.

May 2020: the first audited 100% PoR in the industry

Gate's counter-claim is stronger than most venues': on May 20, 2020 — two and a half years before FTX made reserve proofs a survival requirement — Gate became the first mainstream exchange to receive an audited 100% proof of reserves, an Armanino agreed-upon-procedures report confirming 104% collateralization on BTC liabilities. A second Armanino assessment followed October 19, 2022; Gate open-sourced the audit methodology on GitHub; the program now runs monthly with Hacken as auditor, using Merkle trees plus zk-SNARKs so individual users can verify inclusion without exposing balances.

Context that earns the claim rather than recites it: Kraken invented the PoR practice (2014), but Gate ran the industry's first formal third-party attestation of the modern type — and kept it running continuously since, through the FTX panic when every competitor scrambled to bolt one on. When the October-2022 rumor claimed Gate held only ~53,930 ETH, the exchange answered with the auditor's verified figures — 269,035 ETH across disclosed wallets — the incident-response equivalent of showing your work.

The allegation it never acknowledged

An honest page has to include the contested chapter: blockchain investigators (Elliptic's research and ZachXBT's tracing, surfaced publicly in 2025) attribute a ~$230 million theft in January 2018 — linked to North Korean actors — to the exchange. Gate has never formally disclosed such an incident; its own 2022 statement acknowledges only that "several well-known platforms were attacked in 2018" while stressing Gate users suffered no loss of personal assets. Both things can be true: a treasury-side loss absorbed silently would technically match "users didn't lose" — and so would the allegation being wrong. The fair reading: an unacknowledged $230M event, if accurate, means the balance-sheet absorbed it — which is resilience — while meaning the disclosure failed — which is the thing PoR exists to check.

Adjacent regulatory footnote, also worth stating: in 2025 the Cayman Islands Monetary Authority issued a public notice that Gate has never been licensed there — incorporation-in-the-Caymans ≠ licensed-in-the-Caymans. Its actual license stack sits elsewhere (Malta MiCA, Dubai VARA, CySEC, AUSTRAC) — which is more than most of its tier holds, stated next to the caveat the CIMA notice exists to puncture.

Where Gate stands

The dated read: the longest-operating venue in the corpus — an eleven-year-old cold-wallet breach it repaid, a decade of industry-first reserve verification, a $230M attribution it never disclosed, and a regulatory footprint wider than its reputation suggests. The risks that remain: a track record old enough to contain both redemption and unresolved questions; the widest listing surface in the industry (more listed assets = more counterparty surface, the trade-off for its catalog); and the standing custodial set. For a venue whose first chapter ended in theft, the second — first-mover, continuous, open-sourced PoR — is the most convincing "learned from it" story the CEX class offers.

Frequently asked questions

Was Gate.io ever hacked?

Once confirmed, once alleged. Confirmed: February 2015 — as Bter.com, it lost ~7,170 BTC (~$1.75M) from a cold wallet, shut temporarily, and repaid users from platform revenue over time. Alleged: blockchain investigators (Elliptic/ZachXBT, surfaced 2025) attribute a ~$230M January 2018 theft to the exchange; Gate never formally disclosed it, stating only that no user assets were lost in 2018-era attacks. Since the 2017 relaunch as Gate.io, no documented theft of user funds exists.

What is Gate's proof of reserves?

The industry's first audited version: on May 20, 2020 Gate received an Armanino agreed-upon-procedures attestation confirming 104% collateralization — the first mainstream exchange to publish a verified 100% reserve proof. It has run monthly attestations since (now Hacken-audited), using Merkle trees + zk-SNARKs so users can verify their own inclusion; the methodology is open-sourced on GitHub. Standard caveat applies as to every venue: a snapshot of assets, not a continuous solvency proof.

Is Gate the same as Bter?

Same company, different era. Bter.com was founded April 2013 in China by Lin Han — the 2015 BTC theft happened under that name. It relaunched as Gate.io in 2017 when China's crackdown forced exchanges offshore, and rebranded again to Gate.com in 2025. The continuity matters honestly both ways: the 2015 breach is part of its record, and so is the fact that the same organization built the industry's first audited PoR afterward.

Did Gate lose $230 million in 2018?

Possibly — and the honest answer is that "possibly" is the finding. On-chain investigators attribute a ~$230M January 2018 theft (linked to North Korean actors) to the exchange. Gate never disclosed such an event; its formal position is that users lost nothing in the 2018-era attacks. If the attribution is right, the loss was absorbed at the platform level — which says something real about the balance sheet and something uncomfortable about the disclosure. Treat it as an open question, not a confirmed theft.

Is Gate licensed?

More than its reputation suggests, with one named caveat: licenses/registrations include Malta (MiCA), Dubai (VARA), Cyprus (CySEC), and Australia (AUSTRAC). The caveat is Caymans — the jurisdiction Gate is incorporated in — where CIMA issued a 2025 public notice that it has never been licensed. Incorporation and licensing are different things; Gate's license stack is real, and the CIMA notice is the detail that keeps "regulated" honest rather than decorative.

Is Gate safer than Binance or Kraken?

Different record entirely. Kraken has 14 unbreached years and invented PoR; Binance has SAFU's tested insurance at nine-figure scale; Gate has the longest timeline — a repaid 2015 breach, the industry's first audited PoR, an unacknowledged 2018 allegation, and the widest asset catalog (which is itself a risk surface). Honest ordering: Gate leads on tenure and on having built transparency after being bitten; it trails Kraken on clean-record and trails Binance on demonstrated backstop scale.

NexFlow is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a NexFlow product