Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
BNB Chain’s X account hacked; CZ warns of phishing links

BNB Chain’s X account hacked; CZ warns of phishing links

KriptoworldKriptoworld2025/08/03 16:00
By:by Tatevik Avetisyan

BNB Chain’s official X account was compromised on October 1, with attackers posting phishing links that imitated WalletConnect prompts.

Binance founder Changpeng “CZ” Zhao confirmed the breach and urged users not to click or connect wallets.

SlowMist’s CISO “23pds” linked the phishing domains to the Inferno Drainer group.

Account takeover confirmed by CZ

Zhao said the BNB Chain account was hacked and used to push multiple malicious links.

He warned users to avoid any “Wallet Connect” prompts shared from the compromised handle.

His post noted that security teams had notified X and filed takedown requests for the phishing sites.

BNB Chain’s X account hacked; CZ warns of phishing links image 0 BNB Chain’s X account hacked; CZ warns of phishing links image 1 BNB Chain X Hack Alert. Source: CZ Binance on X

Additionally, coverage across crypto media repeated the warning and highlighted the fraudulent “rewards” and “airdrop” narratives used in the posts. Reports added that, at the time, losses were not confirmed.

By mid-day, the obvious phishing posts were no longer visible on the BNB Chain timeline.

However, confirmation on whether any users connected wallets or lost funds was still pending.

Phishing links mimicked WalletConnect

The campaign relied on links that prompted users to connect wallets, a common tactic to authorize malicious transactions.

Attackers framed the prompts as part of airdrops or reward programs to increase click-through rates.

Reports described the posts as urging quick participation and early payouts, which are typical social-engineering hooks in crypto phishing. Users who clicked risked exposing signing permissions or seed phrases.

Zhao reiterated basic hygiene: treat even “official” links with caution and verify domains before interacting.

He used his personal account to amplify the alert while the compromised handle remained restricted.

SlowMist: domains tied to Inferno Drainer

SlowMist’s chief security officer “23pds” said the phishing domains used a letter-swap trick, replacing the character “i” with “l” to mimic legitimate addresses. He attributed the infrastructure to the Inferno Drainer group.

Inferno Drainer, active since at least 2022, offers phishing-as-a-service kits and turnkey wallet-draining sites to affiliates.

Security outlets and aggregators relayed SlowMist’s warning shortly after the hack surfaced.

A separate SlowMist note suggested the number of impacted users might be limited, based on an observed wallet address tied to the campaign. That assessment remained preliminary.

Response and next steps

According to Zhao, Binance security contacted X to suspend the compromised account and pursued takedowns for the phishing domains. Those actions aim to reduce secondary exposure as cached posts and cross-shares persist.

Newsrooms continued to monitor the account while BNB Chain’s team investigated internally.

A spokesperson cited by one outlet said more information would follow as the inquiry progressed.

Users who engaged with any links were advised by multiple outlets to revoke suspicious approvals and rotate credentials as needed, pending official guidance from the project’s security teams.

Community vigilance urged

Zhao stressed that verified handles can be compromised, so domain checks and manual verification remain essential. He repeated his standard “Stay SAFU” caution in the context of the incident.

Security researchers pointed out that attackers often reuse domain patterns, shorteners, and copy decks across campaigns, so community reports help platforms and registrars move faster.

Until BNB Chain issues a post-incident summary, the safest course is to treat any recent links from the account as untrusted and confirm updates via secondary official channels.

BNB Chain’s X account hacked; CZ warns of phishing links image 2 BNB Chain’s X account hacked; CZ warns of phishing links image 3
Tatevik Avetisyan
Editor at Kriptoworld

Tatevik Avetisyan is an editor at Kriptoworld who covers emerging crypto trends, blockchain innovation, and altcoin developments. She is passionate about breaking down complex stories for a global audience and making digital finance more accessible.

📅 Published: August 4, 2025🔄 Last updated: August 4, 2025

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Nvidia’s Culture of Trust: The Role of Generous Leave in Driving Technological Leadership

- Nvidia offers 22-week paid maternity leave, 12 weeks for non-birthing parents, and 8 weeks of flexible scheduling, ranking No. 2 on Fortune's 2025 Best Workplaces for Parents list. - CEO Jensen Huang prioritizes employee care to attract talent, with 93% of Nvidia parents reporting "deep care" from the company versus 48% at typical U.S. workplaces. - The policy includes surrogacy/adoption coverage, backup childcare, and manager-led flexibility, correlating with 50% higher "extra effort" at work compared t

Bitget-RWA2025/11/18 12:36
Nvidia’s Culture of Trust: The Role of Generous Leave in Driving Technological Leadership

Hyperliquid's Rising Popularity and Entry Barriers: Addressing Institutional Participation and Retail Appetite in Liquid Restaking Derivatives

- Hyperliquid's 2025 retail-driven growth surged via token airdrops and buybacks, reaching $2.15B TVL and 70% perpetual futures market share. - Institutional adoption faces barriers from token dilution risks (10.8B HYPE unlock) and regulatory challenges after $4.9M POPCAT token manipulation losses. - Strategic innovations like HIP-3 and 21Shares' ETF proposal aim to attract institutional capital despite competition from Aster and BNB Chain platforms. - Platform's success hinges on balancing retail momentum

Bitget-RWA2025/11/18 12:32

SEC Obscures Boundaries of Crypto Regulation Amid 2026 Oversight Changes

- U.S. SEC removed crypto from 2026 examination priorities under Trump's deregulatory agenda, shifting focus to cybersecurity and investor protection. - The move reflects normalization of digital assets within mainstream finance, aligning with global trends to apply existing rules to crypto. - While reducing crypto-specific oversight, SEC retains authority to address risks in AI and automated investment tools. - Market sees the shift as pro-industry, but cybersecurity and compliance demands remain critical

Bitget-RWA2025/11/18 12:20
SEC Obscures Boundaries of Crypto Regulation Amid 2026 Oversight Changes

Assessing the HYPE Token: Is a Meme-Based Cryptocurrency Capable of Maintaining Its Price Rally?

- HYPE token surged above $40 in 2025 despite crypto's bear market, driven by whale accumulation and $1.71B futures open interest. - Technical indicators show fading bearish pressure (RSI near 50) but highlight $44.48 resistance and $36.51 support levels. - Meme-inspired HYPE faces credibility challenges compared to transparent platforms like Jump.meme, with unclear utility beyond governance. - Market volatility and regulatory risks persist, contrasting with SOL ETF inflows yet mirroring Monad's failed tok

Bitget-RWA2025/11/18 12:16