CryptoReal
CASE FILE — Sep 20, 2024

BingX Hot Wallet Breach Drains $44.7 Million Across Multiple Chains

Centralized exchange BingX became the latest trading platform to suffer a large-scale hot wallet compromise, with losses eventually tallied at $44.7 million.

On September 19, the Singapore-linked exchange's hot wallets were breached by attackers who moved funds across several blockchain networks simultaneously, a pattern that made the incident harder to trace and contain in real time.

How the alarm was raised

The first public signal came from the crypto research community rather than from BingX itself. Independent researcher Tayvano began cataloguing the addresses draining BingX funds, flagging early on that the attacker was operating across multiple chains at once.

Security firm PeckShield followed shortly after, reporting a suspicious outflow of roughly $13.6 million from BingX-controlled wallets.

BingX itself stayed quiet for close to an hour before issuing a statement that referred only to a "Temporary Wallet Maintenance Notice," without acknowledging an exploit was underway.

The exchange's account of events

BingX's Chief Product Officer, Vivien Lin, later posted a more detailed explanation. According to Lin, the team identified "abnormal network access" at approximately 4 AM Singapore time and suspected a hacker had targeted the hot wallet infrastructure. The company said it activated an emergency response that included urgently moving remaining assets and suspending withdrawals.

Lin characterized the incident as a "minor asset loss," stating that the bulk of user funds remained secure in cold storage. BingX committed to restoring withdrawal functionality within 24 hours and indicated a compensation plan would follow.

The real scale of the losses

That framing did not match the numbers coming from independent monitors. Cyvers reported a much larger exposure, and the final tally — $44.7 million — was confirmed by SlowMist, spread across Ethereum, BNB Chain, Polygon, and other networks.

The involvement of multiple wallets pointed to either a coordinated operation or a single highly capable attacker. Blockchain analysts identified ten confirmed exploiter addresses, plus three additional addresses suspected of interacting with them:

Exploiter Address 1: 0xf7e8033366166f92eb477b7b38e0d47d47b43326

Exploiter Address 2: 0xb0146aec3593410c8307b570af69adf4d74678b3

Exploiter Address 3: 0x940362b46faf7df48af1c8989d809f50466b5fca

Sums referenced in this case file

Exploiter Address 4: 0x1Dd7dAf089C16856155FeFd7e2170966bb6b3AEE

Exploiter Address 5: 0x719981cf7D1a1dC681a1cf0C6B1eeeE090D0FEd6

Exploiter Address 6: 0xf26e64ef4300ca027d2ffedd7d765d7a3906091c

Exploiter Address 7: 0xb77a4a9678315775c4ba89f18f84f87538e748f5

Exploiter Address 8: 0x63dc352ddfc17aa04edac47ce36e186c1e54b02c

Exploiter Address 9: 0x49284f0ab5098d7effb3392124903c081d1b9f7e

Exploiter Address 10: 0xcfc14fa81226074036622976d95897ff84b58d66

Suspected Address 1: 0xc1B5a00871B89175bDC8F3b0de9Be3b29ffD3729

Suspected Address 2: 0x4D9D586567c9feA923c362c35385935Ee7781bf6

Suspected Address 3: 0xf36dd342A1D1C63aAddF9a95226349e527917fF3

Open questions on the root cause

BingX has not disclosed exactly how the intrusion occurred, leaving open the possibility of a phishing attack, an insider compromise, or an undetected weakness in the exchange's wallet security architecture.

A possible Lazarus connection

Hakan Unal, Senior Security Operations Lead at Cyvers, pointed to a behavioral pattern worth noting: "This hacker's behavior—using multiple wallets to swap altcoins into ETH and BNB before consolidating—is consistent with the tactics we've seen in past Lazarus operations." Whether the North Korea-linked group was actually responsible remains unconfirmed, but the technique matches previous cases attributed to it.

Scrutiny of BingX's own record

On-chain investigator ZachXBT weighed in with a pointed rebuttal to BingX's public messaging: "The second part of your statement is ironic considering BingX is known to be unhelpful to all of the victims who have stolen funds go there from pig butchering scams, indian call scams, and irl thefts. Hopefully your security incident will help you reassess your processes as you are among the worst in that regard." The comment underscored a contrast between BingX's plea for sympathy as a hack victim and its past treatment of scam victims whose stolen funds passed through the exchange.

Part of a broader pattern

The BingX incident followed closely on the heels of another Asian exchange breach: just over a week earlier, Indodax lost roughly $25 million to a comparable attack. Taken together, the two incidents reflect mounting pressure on centralized exchange security and raise questions about whether current defenses are keeping pace with increasingly sophisticated attackers.

BingX
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.