LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › GateHub Data Breach (2019)

CRITICAL severityConfirmedHow we verify

GateHub Data Breach (2019): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 4, 2019
GateHub Data Breach (2019)

Reported June 4, 2019. Approximately 1.4M people affected.

CRITICAL
Severity
1.4M
People affected
4
Data types exposed
June 4, 2019
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The GateHub Data Breach (2019) (reported June 4, 2019) exposed Email addresses, Encrypted keys, Mnemonic phrases and Passwords belonging to roughly 1.4M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the GateHub Data Breach (2019) breach?
1.4M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In 2019 a data incident at the cryptocurrency wallet provider GateHub resulted in the later public posting of records covering 1.4 million accounts. The event is one of several that year in which services holding digital-asset credentials were targeted, underscoring the value attackers place on access to wallets and recovery material.

What happened

GateHub acknowledged a breach in June 2019, at that time reporting a smaller number of affected accounts. In October 2019 a data set described as containing 1.4 million GateHub accounts was posted on a hacking forum. The material included email addresses, mnemonic phrases, encrypted master keys, encrypted recovery keys and passwords stored as bcrypt hashes.

Public records do not disclose the precise date or method of the initial intrusion, nor do they confirm whether the June and October figures refer to the same event or to separate incidents.

How a breach like this happens

Incidents involving online wallet platforms often begin with the compromise of web-application infrastructure or third-party services that store user credentials. Attackers may obtain database extracts through stolen administrative access, misconfigured storage, or supply-chain weaknesses. Once obtained, the data can be packaged and shared on forums months after the original intrusion.

Because many such platforms rely on hashed passwords and encrypted key material, the practical value of a data set depends on whether additional information, such as unencrypted recovery phrases, is also present.

Who is GateHub?

GateHub operates as a cryptocurrency wallet and exchange service. Organisations in this sector routinely hold email addresses, login credentials and cryptographic recovery data that, if exposed, can be used to attempt access to digital-asset holdings. A breach at such a service therefore carries implications beyond conventional identity theft, because control of wallet keys can directly affect funds.

The information in question

The October 2019 forum posting was reported to contain email addresses, mnemonic phrases, encrypted master keys, encrypted recovery keys and passwords stored as bcrypt hashes. GateHub’s June statement referred to a smaller set of accounts without publishing a full list of exposed fields. The exact overlap between the two disclosures remains unconfirmed in public statements.

The real-world impact

Individuals whose records appeared in the data set face the possibility that attackers could attempt to use exposed mnemonic phrases or encrypted keys to access associated cryptocurrency wallets. Email addresses and password hashes can also be used in credential-stuffing attacks against other services. For the organisation, the incident adds to the body of publicly discussed breaches affecting digital-asset platforms and may prompt users to migrate accounts or demand stronger protective measures.

If your data was in this breach

Anyone who held a GateHub account in 2019 should treat the exposure of recovery material as a high-priority concern. Practical steps include verifying account status directly with the service and reviewing activity on any linked wallets.

Readers can run a free exposure scan of their email address against known breach data sets to check for further appearances of their information.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

CompanyGateHub security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See GateHub’s full breach history →

More recent breaches

Sonicbids Data Breach (2019)December 30, 2019Avvo Data Breach (2019)December 17, 2019Go Ninja Data Breach (2019)December 17, 2019GameSprite Data Breach (2019)December 17, 2019

Latest breaches

Read GalaxyWarden’s full analysis of the GateHub Data Breach (2019) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram