Approximately 420,000 records referencing Binance accounts were identified among the 149 million exposed login credentials and passwords in a large unprotected database discovered by cybersecurity researcher **Jeremiah Fowler**. This highlights the scale of credential theft targeting cryptocurrency users through devices infected with malware.
This publicly available database was accessible to anyone without encryption or password protection and contained over 96GB of stolen credential data, including email addresses, usernames, passwords, and directly loggable URLs.
According to Fowler's investigation, these credentials appear to have been collected not through direct breaches of the victim platforms themselves, but rather through infostealer (information theft) malware.
The existence of records linked to Binance does not imply that Binance's internal systems were breached. Instead, it is presumed that data was collected from the devices of individual users infected with credential theft software.
Binance records, part of extensive financial exposure
Fowler reported that the dataset includes extensive financial services, cryptocurrency wallets, and credentials associated with trading platforms.
Along with records referencing Binance, the database also included login information associated with bank, credit card, and other cryptocurrency platform accounts, demonstrating that infostealer malware has established itself as a primary means of account theft.
The structure of the dataset revealed circumstantial evidence that was systematically collected.
Records were indexed using reverse host paths and unique hash identifiers, making it easy to categorize them by victim and service.
According to Fowler, the level of systematic structure increases the likelihood that the credentials will be used in automated credential stuffing attacks targeting exchanges and financial platforms.
Also Read: How Europe Became America's Biggest Foreign Owner With $10.4 Trillion U.S. Stock Bet
Government account credential exposure raises additional concerns
In addition to consumer and financial accounts, Fowler verified credentials associated with .gov email domains issued in multiple countries.
Not all government accounts can directly access sensitive systems, but exposed credentials could potentially be exploited as a foothold for identity fraud, targeted phishing, or official network infiltration.
With the inclusion of government-linked accounts, this incident escalates from a simple consumer cybersecurity issue to a matter that could lead to national security and public safety risks depending on the roles of the affected users.
Database exposed to the public for several weeks
According to Fowler, this database could not identify its owner and was hosted on cloud infrastructure with no basic security controls.
After confirming the exposure, he reported directly to the hosting provider, but despite multiple contacts, access restrictions were not imposed for nearly a month, during which time the number of exposed records continued to increase.
The hosting provider refused to disclose who managed the database, and it remains unclear how long this data had been publicly accessible before Fowler's discovery, as well as whether others accessed it during that period.
Currently, the database has been transitioned offline, but Fowler warned that once such datasets are leaked, copies are often redistributed, making it difficult to completely control long-term damage.
Read Next: Are We On The Cusp Of A Bear Market As Crypto Liquidity Drains And Metals Rally?
