Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
BNB Chain’s X account hacked; CZ warns of phishing links

BNB Chain’s X account hacked; CZ warns of phishing links

KriptoworldKriptoworld2025/08/03 16:00
By:by Tatevik Avetisyan

BNB Chain’s official X account was compromised on October 1, with attackers posting phishing links that imitated WalletConnect prompts.

Binance founder Changpeng “CZ” Zhao confirmed the breach and urged users not to click or connect wallets.

SlowMist’s CISO “23pds” linked the phishing domains to the Inferno Drainer group.

Account takeover confirmed by CZ

Zhao said the BNB Chain account was hacked and used to push multiple malicious links.

He warned users to avoid any “Wallet Connect” prompts shared from the compromised handle.

His post noted that security teams had notified X and filed takedown requests for the phishing sites.

BNB Chain’s X account hacked; CZ warns of phishing links image 0 BNB Chain’s X account hacked; CZ warns of phishing links image 1 BNB Chain X Hack Alert. Source: CZ Binance on X

Additionally, coverage across crypto media repeated the warning and highlighted the fraudulent “rewards” and “airdrop” narratives used in the posts. Reports added that, at the time, losses were not confirmed.

By mid-day, the obvious phishing posts were no longer visible on the BNB Chain timeline.

However, confirmation on whether any users connected wallets or lost funds was still pending.

Phishing links mimicked WalletConnect

The campaign relied on links that prompted users to connect wallets, a common tactic to authorize malicious transactions.

Attackers framed the prompts as part of airdrops or reward programs to increase click-through rates.

Reports described the posts as urging quick participation and early payouts, which are typical social-engineering hooks in crypto phishing. Users who clicked risked exposing signing permissions or seed phrases.

Zhao reiterated basic hygiene: treat even “official” links with caution and verify domains before interacting.

He used his personal account to amplify the alert while the compromised handle remained restricted.

SlowMist: domains tied to Inferno Drainer

SlowMist’s chief security officer “23pds” said the phishing domains used a letter-swap trick, replacing the character “i” with “l” to mimic legitimate addresses. He attributed the infrastructure to the Inferno Drainer group.

Inferno Drainer, active since at least 2022, offers phishing-as-a-service kits and turnkey wallet-draining sites to affiliates.

Security outlets and aggregators relayed SlowMist’s warning shortly after the hack surfaced.

A separate SlowMist note suggested the number of impacted users might be limited, based on an observed wallet address tied to the campaign. That assessment remained preliminary.

Response and next steps

According to Zhao, Binance security contacted X to suspend the compromised account and pursued takedowns for the phishing domains. Those actions aim to reduce secondary exposure as cached posts and cross-shares persist.

Newsrooms continued to monitor the account while BNB Chain’s team investigated internally.

A spokesperson cited by one outlet said more information would follow as the inquiry progressed.

Users who engaged with any links were advised by multiple outlets to revoke suspicious approvals and rotate credentials as needed, pending official guidance from the project’s security teams.

Community vigilance urged

Zhao stressed that verified handles can be compromised, so domain checks and manual verification remain essential. He repeated his standard “Stay SAFU” caution in the context of the incident.

Security researchers pointed out that attackers often reuse domain patterns, shorteners, and copy decks across campaigns, so community reports help platforms and registrars move faster.

Until BNB Chain issues a post-incident summary, the safest course is to treat any recent links from the account as untrusted and confirm updates via secondary official channels.

BNB Chain’s X account hacked; CZ warns of phishing links image 2 BNB Chain’s X account hacked; CZ warns of phishing links image 3
Tatevik Avetisyan
Editor at Kriptoworld

Tatevik Avetisyan is an editor at Kriptoworld who covers emerging crypto trends, blockchain innovation, and altcoin developments. She is passionate about breaking down complex stories for a global audience and making digital finance more accessible.

📅 Published: August 4, 2025🔄 Last updated: August 4, 2025

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!