Binance staff and Ukraine’s Cyber Police are investigating the mysterious disappearance of more than $300,000 from a crypto investor’s account
Kyiv, Ukraine. One of the clients of the world’s largest crypto exchange, Binance, has found himself in an extremely unpleasant situation: a significant amount of crypto assets disappeared from his account, equivalent to more than $300,000. What makes this case especially suspicious is that the user himself says he did not initiate any withdrawal transactions and did not grant any permissions. The incident is now being handled by both the exchange and Ukrainian law enforcement.
The story began at the end of August, when the account owner received a notification about an attempted login. The system alerted him to a sign-in with a geolocation pointing to Moscow. The client, who says he had no intention of logging into his profile, immediately rejected the request. However, just six days later, he discovered that a large portion of his crypto assets had vanished. Right after noticing the loss, he contacted Binance support and reported the incident to Ukraine’s Cyber Police.
For security reasons and to ensure a thorough investigation, the victim’s name, the exact amount withdrawn, and other identifying details that could harm the investigation remain confidential. The editors have documentary evidence: screenshots of correspondence with Binance representatives, a detailed timeline of events, and blockchain analysis results.
A security challenge: how could funds be withdrawn from a protected account?
According to the victim, whom we will call Ivan, his Binance account was properly secured. He used a passkey — a modern and secure authentication method that replaces traditional passwords — as well as two-factor authentication (2FA). This means that for any significant action, beyond entering the passkey, an additional confirmation would have been required, usually via an SMS code or an authenticator app. Ivan claims that he did not initiate any withdrawal and did not try to access the platform from a new, unknown device. That is why the suspicious authorization request from Moscow alarmed him, and he immediately expressed his concern by rejecting it.
However, shortly after that, it turned out that a significant amount of crypto assets had been withdrawn from his account. Even after contacting Binance support, the user did not receive a full explanation. According to Ivan, exchange representatives said that the authorization, based on their data, took place from his own device, but they refuse to provide detailed technical information about the withdrawal mechanism, citing internal policy. Binance says full information will be provided only upon an official request from law enforcement.
Binance’s position and possible attack scenarios
The editorial team contacted Binance to comment on this specific case. In response, the company said it does not comment on individual users’ cases, ongoing investigations, or law enforcement requests so as not to interfere with the investigation. At the same time, exchange representatives confirmed their readiness to cooperate with law enforcement in accordance with applicable law.
In correspondence with Binance support, the user was told that the screen with the “Deny” button may have been part of a phishing attack. Also, the difference in geolocation could have been caused by the use of VPNs or proxy servers, although the user himself denies using them at the time of the incident. These explanations, however, do not provide a clear answer as to how exactly the withdrawal operation was created and confirmed.
An interesting detail is the Moscow geolocation. It is worth noting that geolocation determined by IP address is not always absolute proof of a person’s physical location. VPN and proxy technologies can distort the real location. At the same time, it is important to mention that Binance announced a complete exit from the Russian market back in September 2023, selling its local business, and at the beginning of 2024 it stopped supporting Russian rubles in its P2P service.
Historical context and Binance’s security track record
Binance, which has been a leading platform in the cryptocurrency market since 2017, has a user base in the millions. Over the years, the company has repeatedly faced cybersecurity incidents. The most high-profile one was the May 2019 hack, when 7,000 bitcoins were stolen from the exchange’s hot wallet, worth about $40 million at the time. According to the company itself, the attackers used phishing, malware, and gained access to API keys, 2FA codes, and other confidential information. Binance said it covered the losses with its own funds.
In 2022, the Binance-linked BNB Chain blockchain network was attacked. A cross-chain bridge vulnerability allowed an attacker to mint tokens worth hundreds of millions of dollars, but this incident affected blockchain infrastructure rather than the direct compromise of user accounts.
It is also worth mentioning the scandal involving the transfer of data to Russian financial intelligence authorities. In August 2026, Reuters reported that Binance had handed over data of a user who supported Ukraine, which was later used in a criminal case against him in Russia. The exchange responded that it acts in accordance with lawful requests from law enforcement agencies.
Technical aspects: passkeys, 2FA, and potential vulnerabilities
Anton Korzhynskyi, a cybersecurity expert, explains that modern crypto exchanges use multi-layered account protection. In addition to a password or passkey and 2FA, there are mechanisms for verifying new devices, monitoring active sessions, confirming withdrawals, whitelists of allowed addresses, and automatically detecting suspicious activity. However, having a passkey and 2FA is not an absolute guarantee against unauthorized actions.
“It depends on how exactly the exchange has built its authorization logic and which security settings were enabled for a particular account,” Korzhynskyi notes. The expert also emphasizes that one should not rush to connect the suspicious login notification that the user rejected with the subsequent withdrawal of funds. “The transaction could have been created earlier from another session, another device, or through an API. The notification may simply have arrived at roughly the same time,” he explains.
To fully understand the situation, what the exchange’s own systems recorded is key. “The most important thing is not what the user saw on the screen, but what the exchange itself recorded. Which device the transaction was created from, which session, how it was confirmed, and which authentication factors actually worked,” Korzhynskyi stresses.
Regarding the phishing theory, Korzhynskyi says that embedding third-party code into an official exchange app is difficult because of operating system protections. However, malware can run in parallel, mimicking the interfaces of official apps, showing fake windows over real ones, or using access to accessibility features and notifications.
Conclusion: exchange responsibility and advice for users
Can this be considered a problem with the exchange’s own security? According to the expert, this will become clear only after a detailed analysis of Binance logs. If the exchange confirms that the notification was genuine, the user pressed “Deny,” the system recorded it, but withdrawal was still allowed afterward without proper confirmation, that would indicate a critical vulnerability. In such a case, the question of compensation for the user would be logical.
Large crypto exchanges are obliged to respond to such cases as full-scale cyber incidents: preserve logs, check all logins, sessions, devices, and APIs, establish the exact moment a transaction was created and confirmed, and track the movement of funds. In addition, they cooperate with law enforcement by providing information as part of official investigations.
Recommendations for users:
Do not rush to interact with suspicious notifications: If you receive an unexpected login or financial transaction request, do not click links or buttons in the notification. Instead, open the exchange’s official app yourself.
Check your activity history: After logging into your account, review your login and transaction history to make sure there are no unauthorized actions.
If you suspect compromise: Immediately end all active sessions, change your credentials, check API settings, block withdrawals, and contact the exchange’s support team.
Contact law enforcement: In cases of suspected theft of funds, in addition to contacting the exchange, it is important to promptly report the incident to law enforcement authorities.
Roman Spas is the author of a blog about website development, IT news, web project promotion, design and modern technologies. In his materials, he explains complex digital topics in simple language, shares practical advice for website owners, entrepreneurs, marketers and specialists who want to better understand the online environment. The author's main focus is on effective websites, SEO, web design, internet marketing and technological solutions that help businesses develop in the digital space.
Binance staff and Ukraine’s Cyber Police are investigating the mysterious disappearance of more than $300,000 from a crypto investor’s account
Kyiv, Ukraine. One of the clients of the world’s largest crypto exchange, Binance, has found himself in an extremely unpleasant situation: a significant amount of crypto assets disappeared from his account, equivalent to more than $300,000. What makes this case especially suspicious is that the user himself says he did not initiate any withdrawal transactions and did not grant any permissions. The incident is now being handled by both the exchange and Ukrainian law enforcement.
The story began at the end of August, when the account owner received a notification about an attempted login. The system alerted him to a sign-in with a geolocation pointing to Moscow. The client, who says he had no intention of logging into his profile, immediately rejected the request. However, just six days later, he discovered that a large portion of his crypto assets had vanished. Right after noticing the loss, he contacted Binance support and reported the incident to Ukraine’s Cyber Police.
For security reasons and to ensure a thorough investigation, the victim’s name, the exact amount withdrawn, and other identifying details that could harm the investigation remain confidential. The editors have documentary evidence: screenshots of correspondence with Binance representatives, a detailed timeline of events, and blockchain analysis results.
A security challenge: how could funds be withdrawn from a protected account?
According to the victim, whom we will call Ivan, his Binance account was properly secured. He used a passkey — a modern and secure authentication method that replaces traditional passwords — as well as two-factor authentication (2FA). This means that for any significant action, beyond entering the passkey, an additional confirmation would have been required, usually via an SMS code or an authenticator app. Ivan claims that he did not initiate any withdrawal and did not try to access the platform from a new, unknown device. That is why the suspicious authorization request from Moscow alarmed him, and he immediately expressed his concern by rejecting it.
However, shortly after that, it turned out that a significant amount of crypto assets had been withdrawn from his account. Even after contacting Binance support, the user did not receive a full explanation. According to Ivan, exchange representatives said that the authorization, based on their data, took place from his own device, but they refuse to provide detailed technical information about the withdrawal mechanism, citing internal policy. Binance says full information will be provided only upon an official request from law enforcement.
Binance’s position and possible attack scenarios
The editorial team contacted Binance to comment on this specific case. In response, the company said it does not comment on individual users’ cases, ongoing investigations, or law enforcement requests so as not to interfere with the investigation. At the same time, exchange representatives confirmed their readiness to cooperate with law enforcement in accordance with applicable law.
In correspondence with Binance support, the user was told that the screen with the “Deny” button may have been part of a phishing attack. Also, the difference in geolocation could have been caused by the use of VPNs or proxy servers, although the user himself denies using them at the time of the incident. These explanations, however, do not provide a clear answer as to how exactly the withdrawal operation was created and confirmed.
An interesting detail is the Moscow geolocation. It is worth noting that geolocation determined by IP address is not always absolute proof of a person’s physical location. VPN and proxy technologies can distort the real location. At the same time, it is important to mention that Binance announced a complete exit from the Russian market back in September 2023, selling its local business, and at the beginning of 2024 it stopped supporting Russian rubles in its P2P service.
Historical context and Binance’s security track record
Binance, which has been a leading platform in the cryptocurrency market since 2017, has a user base in the millions. Over the years, the company has repeatedly faced cybersecurity incidents. The most high-profile one was the May 2019 hack, when 7,000 bitcoins were stolen from the exchange’s hot wallet, worth about $40 million at the time. According to the company itself, the attackers used phishing, malware, and gained access to API keys, 2FA codes, and other confidential information. Binance said it covered the losses with its own funds.
In 2022, the Binance-linked BNB Chain blockchain network was attacked. A cross-chain bridge vulnerability allowed an attacker to mint tokens worth hundreds of millions of dollars, but this incident affected blockchain infrastructure rather than the direct compromise of user accounts.
It is also worth mentioning the scandal involving the transfer of data to Russian financial intelligence authorities. In August 2026, Reuters reported that Binance had handed over data of a user who supported Ukraine, which was later used in a criminal case against him in Russia. The exchange responded that it acts in accordance with lawful requests from law enforcement agencies.
Technical aspects: passkeys, 2FA, and potential vulnerabilities
Anton Korzhynskyi, a cybersecurity expert, explains that modern crypto exchanges use multi-layered account protection. In addition to a password or passkey and 2FA, there are mechanisms for verifying new devices, monitoring active sessions, confirming withdrawals, whitelists of allowed addresses, and automatically detecting suspicious activity. However, having a passkey and 2FA is not an absolute guarantee against unauthorized actions.
“It depends on how exactly the exchange has built its authorization logic and which security settings were enabled for a particular account,” Korzhynskyi notes. The expert also emphasizes that one should not rush to connect the suspicious login notification that the user rejected with the subsequent withdrawal of funds. “The transaction could have been created earlier from another session, another device, or through an API. The notification may simply have arrived at roughly the same time,” he explains.
To fully understand the situation, what the exchange’s own systems recorded is key. “The most important thing is not what the user saw on the screen, but what the exchange itself recorded. Which device the transaction was created from, which session, how it was confirmed, and which authentication factors actually worked,” Korzhynskyi stresses.
Regarding the phishing theory, Korzhynskyi says that embedding third-party code into an official exchange app is difficult because of operating system protections. However, malware can run in parallel, mimicking the interfaces of official apps, showing fake windows over real ones, or using access to accessibility features and notifications.
Conclusion: exchange responsibility and advice for users
Can this be considered a problem with the exchange’s own security? According to the expert, this will become clear only after a detailed analysis of Binance logs. If the exchange confirms that the notification was genuine, the user pressed “Deny,” the system recorded it, but withdrawal was still allowed afterward without proper confirmation, that would indicate a critical vulnerability. In such a case, the question of compensation for the user would be logical.
Large crypto exchanges are obliged to respond to such cases as full-scale cyber incidents: preserve logs, check all logins, sessions, devices, and APIs, establish the exact moment a transaction was created and confirmed, and track the movement of funds. In addition, they cooperate with law enforcement by providing information as part of official investigations.
Recommendations for users:
Roman Spas
Roman Spas is the author of a blog about website development, IT news, web project promotion, design and modern technologies. In his materials, he explains complex digital topics in simple language, shares practical advice for website owners, entrepreneurs, marketers and specialists who want to better understand the online environment. The author's main focus is on effective websites, SEO, web design, internet marketing and technological solutions that help businesses develop in the digital space.
Recent posts
$300,000 From Binance: How to Protect Your
22.09.2026Apple M5 Ultra vs RTX 5080: Blender
22.09.2026Xbox: Patent for In-Game Advertising – Microsoft’s
21.09.2026Categories