CSIDB logo
Incident

Binance

Incident posture

Attack window
Mar 2018
Location
China
Status
Historical
CIA posture
Available to members
Updated
2025-11-30 00:00

Linked entities

Victim
Binance
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cryptocurrency exchange experienced unauthorized trading activity where users' altcoins were sold and converted into Bitcoin and other assets, linked to compromised API keys obtained through a phishing campaign involving a fraudulent clone website. Attackers created dormant API keys using stolen credentials and executed coordinated trades during a brief window, manipulating the price of a low-liquidity coin to profit from artificial inflation. The platform suspended trading, reversed suspicious transactions, and froze targeted coins, mitigating further losses, though some stolen Bitcoin remained unrecoverable due to counterparty transactions. While most affected users regained their funds, the incident underscored vulnerabilities in third-party API key management and the effectiveness of phishing tactics against digital asset platforms.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On March 7, 2018, Binance users reported unauthorized trading activity where their cryptocurrency holdings were automatically sold and converted into Bitcoin and other digital assets without consent. Panicked traders observed altcoins being liquidated, with some accounts showing newly created API keys despite having two-factor authentication enabled. Binance initially stated no evidence indicated a direct breach of its platform infrastructure but later identified the root cause as compromised API keys linked to third-party trading bots. The exchange temporarily suspended all trading activity and initiated investigations into irregular transactions. Forensic analysis revealed attackers had executed a prolonged phishing campaign through a counterfeit domain mimicking Binance’s legitimate website (binance.com), harvesting login credentials from victims who unknowingly interacted with the fraudulent site.

The attackers exploited stolen credentials to generate dormant API keys on genuine Binance accounts, which they activated during a targeted two-minute trading window. Fraudsters concentrated on manipulating Viacoin (VIA), a low-liquidity cryptocurrency, by using stolen Bitcoin to purchase VIA and subsequently selling it for profit. Binance froze all VIA holdings to disrupt further malicious trades and reversed unauthorized transactions where possible. However, Bitcoin spent on VIA purchases could not be recovered because counterparties in these trades were legitimate accounts unrelated to the attackers. The exchange restored affected users’ original asset balances where feasible and reiterated security guidance urging customers to safeguard credentials. Users expressed relief at fund recovery but acknowledged Binance’s policy of non-compensation for phishing-related losses. The incident underscored operational risks posed by phishing campaigns targeting cryptocurrency platforms and their users.

Sources

Sources available to members: 1 source.

CSIDB