BingX Hack
What happened
On September 20, 2024, BingX detected unauthorized access targeting a hot wallet. Public investigations estimated losses in the tens of millions of dollars, while BingX said most assets were held in cold storage and withdrawals were suspended to contain the incident.
The confirmed failure was compromise of a hot-wallet security boundary. The exact root cause remains unknown in BingX’s public materials; no specific key leak or malware path has been established.
Case & protocol details
How it happened
- An attacker accessed a BingX hot wallet used for operational withdrawals.
- Assets were transferred out across several token networks before the exchange completed containment.
- BingX halted deposits and withdrawals, investigated the wallet activity and committed to covering verified losses.
- The exchange’s public FAQ describes an unauthorized intrusion but does not identify how credentials or keys were obtained.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report 2024 Global Web3 Security Report beosin.com
- analysis Website reference x.com
- analysis Website reference cointelegraph.com
- analysis BingX Hot Wallet Incident FAQ bingxservice.zendesk.com
- analysis Path of Stolen Funds in the BingX Incident fsa.go.jp
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.