Back to dashboard
Tuesday, May 7, 2019 at 17:15 UTC

Binance

API keys + 2FA phished from users; SAFU covered losses.

Recovered
Funds stolen
$40.70M
Recovered
$40.70M100%
Still outstanding
$0.00M
Chain
Bitcoin
Category
CEX
Attack vector
Phishing
Reported by
SlowMist
Incident ID
h2019-2

Exploit & recovery timeline

  1. May 7, 2019 · 15:15 UTC
    Attack preparation

    Attacker wallets funded and staged ahead of the phishing exploit against Binance.

  2. May 7, 2019 · 17:15 UTC
    Exploit executed

    $40.7M drained from Binance on Bitcoin via Phishing.

  3. May 7, 2019 · 18:15 UTC
    Detected by SlowMist

    SlowMist flagged the anomalous transactions and published an initial alert.

  4. May 7, 2019 · 21:15 UTC
    Protocol response

    Binance paused affected contracts or withdrawals and began tracing outbound flows.

  5. May 8, 2019 · 17:15 UTC
    Funds traced

    Stolen assets followed through mixers, bridges, and exchange deposit addresses.

  6. May 14, 2019 · 17:15 UTC
    Full recovery

    $40.7M returned to users — negotiation, freezes, or a whitehat return closed the incident.