API keys + 2FA phished from users; SAFU covered losses.
Attacker wallets funded and staged ahead of the phishing exploit against Binance.
$40.7M drained from Binance on Bitcoin via Phishing.
SlowMist flagged the anomalous transactions and published an initial alert.
Binance paused affected contracts or withdrawals and began tracing outbound flows.
Stolen assets followed through mixers, bridges, and exchange deposit addresses.
$40.7M returned to users — negotiation, freezes, or a whitehat return closed the incident.