A user of the crypto exchange Binance contacted AIN, saying that crypto assets worth more than $300 thousand were stolen from his account. According to him, he did not create or confirm this transaction.
In late August, the user received an authorization request with a geolocation in Moscow and rejected it. Six days later, he noticed that funds were missing from his account and contacted Binance support and the Cyber Police of Ukraine.
Currently, the circumstances of the incident are being investigated by law enforcement and by the Binance company itself. At the user’s request, AIN does not disclose his name, the exact amount of the withdrawn funds, IP addresses, and other data that could identify him or harm the investigation.
AIN recreated the timeline of events and figured out how an operation could be carried out on an account protected by a passkey and two-factor authentication—how the situation is explained by Binance and what a cybersecurity expert recommends to reduce the risk of similar incidents.
A login request from Moscow and a withdrawal of funds. Incident details
Binance is the world’s largest centralized cryptocurrency exchange by trading volume, operating since 2017. The platform allows users to buy, sell, exchange, and store crypto assets. It currently has 300 million registered users worldwide.
According to Ivan (his name has been changed for security reasons), his Binance account was protected by a passkey and two-factor authentication. Before the incident, he did not initiate a withdrawal and did not try to log into Binance from a new device. That’s why he rejected the authorization request—even with geolocation in Moscow.
Later, it was found that around the same time, crypto assets worth the equivalent of more than $300 thousand were moved out of his account.
“Binance support says the authorization happened specifically from my device, but refuses to provide details about how the withdrawal was carried out. They say they will provide the detailed information only upon a request from law enforcement,” Ivan says.
He contacted the Cyber Police of Ukraine and completed the relevant submission.
What Binance responded
AIN’s editorial team contacted Binance for a comment about the incident.
The company stated that it does not comment on individual users’ cases or on ongoing investigations.
“Under our internal policy, Binance does not comment on ongoing $ investigations, matters related to individual users, or specific requests from law enforcement agencies, and does not disclose information that could hinder the course of an investigation. We cooperate with law enforcement agencies in accordance with current legislation and established procedures,” the company explained in response to the editorial request.
Ivan also corresponded with the support service. Binance did not provide the user with detailed technical data, explaining that it could pass the relevant information to law enforcement within the framework of an official investigation.
But in one of the messages, a Binance representative suggested that a screen with a Deny button could be part of a phishing attack.
The support team also explained the difference in geolocation as possibly being due to the use of a VPN or a proxy. At the same time, the user claims that he did not use them at the time of the incident.
These explanations do not make it possible to determine exactly how the withdrawal operation of more than $300 thousand was created and confirmed.
A separate explanation is also needed for the Russian geolocation during an authentication request. After all, the geolocation listed in the authorization request—“Moscow”—by itself does not prove that the person attempting to access the account was physically in Russia. IP geolocation can be affected by, among other things, a VPN.
But even before that, in September 2023, the company announced a complete exit from the Russian market and the sale of CommEX’s local business. In early 2024, Binance also stopped supporting Russian rubles in its P2P service—that is, between users—and limited its use for Russian citizens and residents.
What is known about Binance and its security
Over almost 10 years of its operation, Binance has faced major incidents in cybersecurity, including public ones.
In May 2019, the company reported a breach in which 7 thousand bitcoins were stolen from its “hot” wallet—an internet-connected storage of crypto assets for transactions. At the time, this was approximately $40 million.
According to Binance, the attackers used phishing, malicious software, and other methods, obtaining, in particular, users’ API keys, two-factor authentication codes, and potentially other information as well. The company said it covered the losses with its own funds.
In 2022, an attack targeted the Binance-linked BNB Chain blockchain network. Due to a vulnerability in the cross-chain bridge, the attacker was able to create tokens worth hundreds of millions of dollars. This incident involved blockchain infrastructure, not the compromise of Binance users’ accounts.
Binance told Reuters that it responds to lawful requests from law enforcement agencies in accordance with applicable legal procedures.
How could the money be withdrawn if the account had a passkey and 2FA?
Anton Korzhynskyi, a cybersecurity expert and Head of the Triage Team at BugStream, explains in a comment for AIN that crypto exchanges usually protect accounts on multiple levels.
These include a password or passkey, two-factor authentication, checks for new devices, control of active sessions, confirmation of withdrawals, whitelists of addresses, and automatic detection of suspicious activity.
At the same time, having a passkey and 2FA does not mean that any operation is impossible without repeated confirmation.
“It depends on how the exchange built its authorization logic and what security settings were enabled for a particular account,” Korzhynskyi explains.
The expert also does not advise automatically linking a request in which the user clicked Deny to the withdrawal of funds.
“In a situation where a person clicked ‘deny,’ and a minute later saw a withdrawal of funds, I wouldn’t rush to directly connect these two events. The operation could have been created earlier from another session, another device, or via an API. The notification could simply have arrived at roughly the same moment,” he says.
To determine what really happened, data from the exchange itself is needed.
“The most important thing is not what the user saw on the screen, but what the exchange itself recorded. Which device the operation was created from, which session, what method it was confirmed with, and which authentication factors actually worked,” Korzhynskyi explains.
One of the versions mentioned by Binance support was phishing.
According to Korzhynskyi, it’s quite difficult to simply embed third-party code into a real official exchange app. On iPhone and Android, app signing and app isolation mechanisms are in place.
At the same time, malicious software on the phone can operate alongside the legitimate app.
“For example, showing a fake window on top of the app, getting access to ‘accessibility settings’ or notifications, replacing part of the interface. For the user, it can sometimes look as if everything is happening inside the real exchange app,” the expert explains.
Can we talk about a security problem with the exchange
According to Korzhynskyi, what will be of fundamental importance is what the systems of Binance itself recorded.
“If the exchange confirms that the notification was genuine, the user clicked ‘deny,’ the system recorded it, but after that it still allowed the withdrawal without proper confirmation, then that’s already a serious problem on the exchange’s side itself. In that case, one can talk about a logic error in authorization or another critical vulnerability. But until technical data is obtained, this is only one of the possible explanations,” the expert says.
In his view, in such cases the exchange should respond as to a full-fledged cyber incident: preserve logs, check all logins, sessions, devices, and APIs, determine the exact moment when the transaction was created and confirmed, and trace the movement of funds.
If it turns out that the cause was a vulnerability or an error on the exchange’s side, then, according to the expert, the issue of compensation to the user is logical. The specific legal responsibility will depend on the exchange’s rules and the jurisdiction in which it operates.
“Large crypto exchanges also cooperate with law enforcement agencies. They are not required to provide data to anyone by an ordinary request, but within an official investigation they may provide information about accounts, logins, IP addresses, devices, and transactions. That’s why in such cases it’s important to contact not only the exchange’s support, but also law enforcement quickly.”
How can you protect your crypto wallets from illegal withdrawals?
If a user receives an unexpected login or financial transaction request even from an apparently official app, Korzhynskyi advises in such a situation not to rush to interact with the notification, but instead to open the app independently, go to the login and transaction history, and check what is happening with the account.
If there is a suspicion of compromise, the expert recommends ending all active sessions, changing credentials, checking the API, blocking withdrawals, and contacting the exchange’s support.
