Binance Hack

REPORTED LOSS $41.7M
High Compromised API keys and two-factor authentication codes Bitcoin

What happened

On May 7, 2019, attackers withdrew about 7,000 BTC, then worth roughly $41.7 million, from Binance's Bitcoin hot-wallet flow in one unauthorized transaction. Binance said compromised user API keys and two-factor authentication codes were used in a coordinated account-level attack. The incident affected the centralized exchange's withdrawal operations, not a smart contract.

Technical Root Cause

Centralized exchange account and API-credential compromise combined with a withdrawal-control failure. No smart-contract vulnerability was publicly disclosed.

Case & protocol details

Classification Centralized exchange account compromise
Protocol Type Exploit/Access control
Official Website www.binance.com/
Protocol Twitter/X @binance

How it happened

Binance said attackers collected API keys, 2FA codes, and potentially other information through phishing, viruses, and other methods that it had not fully identified. They coordinated activity across accounts and produced a withdrawal that passed the exchange's existing checks before alerts triggered and withdrawals were halted. The public record does not establish the initial intrusion route or a protocol-level software flaw.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.