Key points to remember
As explained by Jimmy Su, the Chief Security Officer of Binance, in this article, recent revelations that Binance user credentials have appeared on the dark web stem from devices infected with malware, not from a breach of Binance's systems.
The type of malicious software (malware) known as InfoStealer (data theft) is an increasingly widespread threat that targets credentials stored in browsers across all sectors, including the cryptocurrency sector.
Binance actively monitors such incidents, informs affected users, and helps them protect their accounts, but user vigilance remains essential.

In recent days, allegations have emerged incriminating Binance in a potential data leak. Claims based on the appearance of user credentials on dark web forums. We want to clarify that our internal investigations show no indication of compromise of Binance systems.
The credentials in question appear to come from infections by malware on individual users' devices. These credentials were, more specifically, collected by a known actor operating on dark web markets and using a category of malware called InfoStealers to retrieve data from compromised browsers.
This is not an isolated case: our security team continuously monitors dark web sources and malware campaigns to identify potential threats to our users. When we detect credentials linked to Binance accounts, we act quickly: we initiate password resets, revoke active sessions, and assist affected users in recovering their accounts.
A significant challenge in cybersecurity
Although cryptocurrency platforms are a popular target, the threat of InfoStealer malware is much broader. According to Kaspersky, over two million credit card details were leaked last year due to these malware campaigns. This number is only increasing.
Binance's internal data confirms this trend. In recent months, we have identified a significant increase in the number of users whose credentials or session data appear to have been compromised by InfoStealer malware infections. These infections do not originate from Binance. Instead, they generally affect personal devices where credentials are saved in browsers or automatically filled on websites.
What is InfoStealer malware?
InfoStealer malware is a category of malicious software designed to extract sensitive data from infected devices without the victim's knowledge. This includes passwords, session cookies, crypto wallet details, and other valuable personal information.
These tools are widely available through the malware-as-a-service model. For a subscription fee, cybercriminals can access advanced malware platforms that offer dashboards, customer support, and automatic data exfiltration to command and control servers. Once stolen, the data is sold on dark web forums, Telegram channels, or private marketplaces.
The damage caused by an infection via an InfoStealer is not limited to a single compromised account. Compromised credentials can lead to identity theft, financial fraud, and unauthorized access to other services, especially when credentials are reused across multiple platforms.
InfoStealer malware is often distributed through phishing campaigns, malicious advertisements, Trojan software, or fake browser extensions. Once on a device, they scan stored credentials and transmit them to the hacker.
Here are the most common distribution vectors:
Phishing emails containing malicious attachments or links;
Fraudulent downloads or software from unofficial app stores;
Game mods and pirated applications shared via Discord or Telegram;
Malicious browser extensions or add-ons;
Compromised websites that silently install malware (drive-by downloads).
Once activated, InfoStealer malware can extract passwords stored in the browser, autofill entries, clipboard data (including cryptocurrency wallet addresses), and even session tokens that allow hackers to impersonate users without knowing their login credentials.
Here are some signs that may suggest an InfoStealer infection on your device:
Unusual notifications or extensions appearing in your browser;
Unauthorized login alerts or unusual account activity;
Unexpected changes to security settings or passwords;
Sudden slowdowns in system performance.
The most sought-after software: popular InfoStealer software targeting Windows and MacOS
In the past 90 days, our analyses have highlighted several significant variants of InfoStealer malware targeting both Windows and MacOS users. For Windows users, RedLine, LummaC2, Vidar, and AsyncRAT are among the most widespread software.
RedLine Stealer is known for collecting login credentials and cryptocurrency-related information from browsers.
LummaC2 is a threat that is gaining increasing popularity, having integrated techniques to bypass modern browser protections such as application-related encryption, and is now capable of stealing cookies and cryptocurrency wallet details in real time.
Vidar Stealer focuses on exfiltrating data from browsers and local applications, with a notable ability to retrieve crypto wallet credentials.
AsyncRAT allows hackers to monitor victims remotely by logging keystrokes, capturing screenshots, and deploying additional payloads. Cybercriminals recently used AsyncRAT again for cryptocurrency-related attacks, harvesting credentials and system data from compromised Windows machines.
Atomic Stealer has become a significant threat to MacOS users. This tool is capable of extracting credentials, browsing data, and cryptocurrency wallet information from infected devices. Distributed via hacker channels as a service, Atomic Stealer leverages native AppleScript for data collection, posing a substantial risk to both individual users and organizations using MacOS. Poseidon and Banshee are among the other notable variants targeting MacOS.
The counterattack from Binance
As part of our security protocols, we:
Monitor marketplaces and dark web forums for user data leaks;
Alert affected users and initiate password resets;
Revoke compromised sessions;
Provide clear guidance on device protection and malware removal.
Our infrastructure remains secure, but the theft of credentials from infected personal devices is an external risk that we all face, making it more important than ever to educate users and promote cyber hygiene.
How to protect yourself from fake apps?
First, use antivirus and anti-malware tools and perform regular scans. Malwarebytes, Bitdefender, Kaspersky, McAfee, Norton, Avast, and Windows Defender are among the reputable free tools. For MacOS users, it is recommended to use the Objective-See anti-malware tool suite, which includes LuLu, KnockKnock, ReiKey, BlockBlock, RansomWhere?, and OverSight.
Remember that summary scans generally do not work correctly because most malware automatically deletes the step one files as soon as the initial infection occurs. Always perform a full disk scan to ensure optimal protection.
Here are some practical measures you can take to reduce your exposure to this threat and many other cybersecurity threats:
Enable two-factor authentication (2FA) using an authentication app or hardware key.
Avoid saving passwords in your browser. Consider using a dedicated password manager.
Download software and applications only from official sources.
Keep your operating system, browser, and all your applications up to date.
Periodically review the authorized devices in your Binance account and remove unfamiliar entries.
Use a withdrawal address whitelist to limit the possible destinations for funds.
Avoid using public or unsecured WiFi networks when accessing sensitive accounts.
Use unique credentials for each account and update them regularly.
Follow security updates and best practices from Binance and other trusted sources.
Immediately change passwords, lock accounts, and report via Binance customer service channels if you suspect a malware infection.
You can discover our comprehensive security guide offering 14 tips for additional ideas on protecting your account.
Staying safe in a constantly evolving threat landscape
The growing importance of the InfoStealer threat serves as a reminder of the evolution and spread of cyberattacks. While Binance continues to invest heavily in platform security and dark web monitoring, protecting your funds and personal data also requires action on your part.
By staying informed, adopting security habits, and keeping their devices virus-free, users can significantly reduce their exposure to threats such as InfoStealer malware.
If you believe your account may have been affected, or if you notice suspicious activity, please contact us through the official customer service channels. Security is a shared responsibility, and we are here to help you.
