Binance user loses $1 million due to Chrome plugin

Tomcat

Professional
Messages
2,689
Reaction score
917
Points
113
The hacker gained control of the account of a Chinese trader on Binance, without having a password, and also without 2FA confirmation. After a series of transactions, the attacker withdrew assets worth $1 million.

我成了币圈卧底的牺牲品,币安账户里100万美元灰飞烟灭

直到现在我整个人还是懵的,这几乎是我这几年全部的积蓄。… pic.twitter.com/sSNUTXFZsc
— Nakamao (@CryptoNakamao) June 3, 2024

The incident occurred on May 24. In the process, the investor did not receive any notifications from the security service, according to him.

The experts involved determined that the hacker intercepted the user's session through a malicious plug-in for the Chrome browser called AggrTrade using cookies. Open source software provides aggregator services. The solution is actively promoted by many opinion leaders and some thematic Telegram channels, the trader noted.

On May 29, the team of the original AggrTrade platform warned about a fraudulent extension using its brand. According to them, the scam from 2022 is aimed at Bitget, Kraken, Binance and other exchanges. An active scam promotion campaign involving influencers began in March 2024.

Security Breach Alert: We've discovered a fraudulent Chrome extension using our brand AggrTrade. This scam has targeted exchanges like Bitget, Kraken, Binance, and others since 2022. In March 2024, a promo campaign on X & Telegram used crypto influencers to endorse it.
— AggrTradeApp (@AggrTradeApp) May 29, 2024

As a result of the incident, the investor had a number of complaints about the work of the exchange's support service. Binance specialists were extremely slow to respond to his requests, the user claims. He contacted the team while the hacker was still active in the account to prevent the withdrawal of funds, but it still happened.

It took Binance employees more than a day to access the KuCoin and Bitcoin exchanges. Gate.io with a request to freeze the stolen assets, which already turned out to be useless.

The user noted that in early March, there were rumors that at least one account on Binance was intercepted using a fraudulent plugin. Allegedly, the incident then caused a reaction from the exchange's CEO Richard Teng, who announced the launch of an investigation. Therefore, the investor believes that the platform team knew about the problem, but did nothing to solve it for a long time.

"The reason I invested a large amount of stablecoins on Binance is because of trust. However, when I was faced with risks, a number of actions of the platform left strange feelings, " he wrote.

OKX user was robbed of $2 million using AI

According to journalist Colin Wu, an OKX trader from Japan has lost more than $2 million in assets.

An OKX user disclosed today that hackers purchased his personal information and used AI to create fake videos. Hackers used these to change the victim's OKX passwords and even 2FA. More than $2 million US were stolen. Be wary of Deepfakes and personal data leaks.…
— Wu Blockchain (@WuBlockchain) June 3, 2024

The attackers acquired his personal data leaked to the network in Telegram. Then they entered the exchange via the investor's email address, claiming a forgotten password.

Hackers also used an AI-synthesized video to change the linked mobile phone number. Thus, they were able to confirm their actions through Google Authenticator.

Within a day, the trader's funds were withdrawn from his account on the exchange.
 
Binance co-founder Yi He did not recognize the responsibility of the crypto exchange for the fact that a security breach led to the loss of $1 million by the client.

"Look carefully: this user's account was hacked because his own computer was attacked. After the hack, the hacker was unable to withdraw funds, so he sold the victim's coins, which led to trading losses," she said.

On June 3, it became known that a hacker gained control of the account of a Chinese trader on Binance, without having a password and access to two-factor authentication. After a series of transactions, the attacker withdrew assets worth $1 million.

According to security experts, the attacker intercepted the user's session through a malicious plugin for the Chrome browser called AggrTrade using cookies.

During the attack, the investor did not receive any alerts from the Binance security system. The trader also noted the slow response of support staff.

In response, the Binance customer service wrote to the user that during the incident, "a hacker stole the login status of your account through the plugin and impersonated you to perform operations and transactions."

用户您好,对于您的遭遇我们非常遗憾,在客服、安全和风控的同事经过案件分析,本着“公开透明”的原则在此复原场景:

1. 事件发生的原因是您的电脑本身被黑客攻破… https://t.co/ir75ThfkR0
— 币安Binance华语|Web3钱包已上线 (@binancezh) June 3, 2024

According to the exchange, security officers processed the trader's request to freeze his account within "one minute and 19 seconds" from the moment of receipt. However, by that time, the hacker had already completed several transactions using leverage on the compromised account:

"We sympathize with your situation, but according to the information we have received so far, the reason for the loss of your assets is that your respective devices were manipulated due to the installation of malicious plugins. Unfortunately, we do not have the ability to compensate for such cases that have nothing to do with Binance."

The victim herself disagreed with this assessment, suggesting that the company "knew about the malicious plugin for a long time", and also connected the attacker's address with other cybercrimes "three to four weeks ago".
 
Top