$43 Million Stolen in Major Security Breach

AD 4nXeLTSd M2R0zu6bvikcwNNauRmsU9ph1S2dMs45InadfzACZkAA2RXawrddwc2xTk6KuMFiJw2Uc4zi5JP76TyMvUgsf9XoaE31fIZ881Oq3hGu8TQAKWca71CFYTjGGyc3DGiQcMMEcqUTYA910dG5Et09pdeLXDfgousC CpRgZsFxZYBlps?key=74 t7

DESC: This article describes how user funds were stolen in the BingX exchange hack. The amount of damage in the BingX hack is $43 million. 

BINGX HACK 

On Friday morning, September 20, 2024, unknown hackers hit BingX for an initial estimated $43 million.  Singapore-based crypto exchange BingX suffered a security breach of its hot wallet system, resulting in a significant loss of funds. The hack caused BingX to lose at least $43 million.

Today, it was announced that the hot wallet exchange of the centralized exchange BingX was attacked by hackers: 

AD 4nXcF1fxKeuvSKYth4XUhCckozZKZVhxqbYNbLg5yfR4G0i9BbckS0Ff1Qffi86Af9kpzjl6jfxQNdaBXSnRqyIeXL8vVnmJbvmBPK8dAeZpnU2h6sKOrZyeCUJtFq8t5fk90fhZpOmWU1rj0tycmcV6Zu79STOFQQFOBPnGxSAyAiUDkAfLtonM?key=74 t7

Figure 1 – Official statement of the exchange on the social network X.com

According to Chief Product Officer Vivien Lin, the technical team detected suspicious network access around 4 o’clock Singapore time, indicating a hacker attack on the BingX hot wallet. A contingency plan to transfer assets and suspend withdrawals was activated. 

Currently, withdrawals are temporarily suspended for verification and security enhancements. 

Technical support claims that withdrawals will resume within 24 hours, and a plan is being prepared to compensate for lost funds: 

AD 4nXcyDEHABklY MfY46ziZiQAkNuCHpSa69xwMq75hv9bPt1tZnAuPBdb9YmYPO1SJMy6j4tOGTShgvB5lM5TG5KODFPp5vGXfeYAIeBD8FcSAieL72IK6ui46vDwdFNP8Tj1jalTEgKlt8cueJ1RU mNi2JStvp589Tey 5CobL xR2hlgMJRWY?key=74 t7

Figure 2 – Product director Vivian Lin’s statement about the X.com social networking site

The amount of damage caused by the BingX hack

According to statements from top officials of the centralized platform, the stolen funds were “insignificant and will be refunded”

According to Hot Wallet’s ArbitrageScanner.io:

AD 4nXf5kNSB9kShd0UhD XMGZqGr4keA1Q dpQKeBbEpRqIegOIBO48 g0 y1GPfuoTubJYzZptu0AXUwKCX2gxnPo e Iq5yWgluBbMVY4wiNB12tIs3HwgE vYiu3moCzhUT8UhSH8 Xu2 l1Ydp9p30zfcYYznCUxPJl89eb00 zLG3uZYlmQ?key=74 t7

Figure 3 – BingX exchange hot wallet (0xa88) 

Withdrawals from the alleged hacker’s wallet were recorded: 

AD 4nXddznzR20ldGP6sAa0FPbdIa1Eym5ZZBZUaaf5NJKmlhrH1IeFw1jxMX9tPPwhKpqSPPIZcYbqE2IUa WSHaaDByrMkGgSlpdvT6nAe3JT3M1BYhUrymYazziROkDn4jWBRBj6jrWimRh8nUh8FS5sClEOVxaBdsP M3jMXDR4ETykL5kHO to?key=74 t7

Figure 4 – Receipts to the hacker’s wallet (0x940) 

The hacker immediately sold part of the funds received through decentralized sites: 

AD 4nXfQywJusUvGUV1BNLOeSAzQMSTyjPOjIx4CTgGXEj5V95YBkyMeLzhIhd s5JRsujHNWcP7cw3LRYOy3pFQlAF 5icS6TB9oBvfG6tkR4p 0k sw43eWKmEs9HsFZAVdQnw6fQExi6sd5Bw3fps UOGEWFdMdPcOz3AAoWGwsVqCPEc3L hX4Q?key=74 t7

Figure 5 – Swipes of the hacker’s stolen wallet funds (0x940) 

The link to the hacker’s wallet can be found here 

The hacker is currently holding funds at the BingX Deposit address: 

AD 4nXddbdzGn3lyRCippfY XEn4ViBfMKllaev9EfNS2zUhd3EbLvtFpWs8k UTl 6MvmDiNc TQVuzyesgEs2zWRHgbOK k dhCcuRbLkCnhy yY3v Oq1DbT9omWF9 yi6m9Q QFDsaH9JrEParJP8wYXm wtFHWhQ klUrmuG0exN8O06XtFpbE?key=74 t7

Figure 6 – Wallet Transfer (0x940) 

The amount of money in the wallet that was transferred from the hacker’s wallet is estimated at $16.5 million.

AD 4nXdy2m6nud wlAc16wQbABWyc3YhvBqxIxO2bKb4SGQqKdrPeTLFVFl5MnSQmQE1maMkQsHNW HvoWv4UvP3fFvghEeTmygvi1Uw4KDGcvGSwecyfcaLWrnZLj4U8NETU7tsihyl5fO7Gz1Zk gde2JuiGBnd8L2 BYoO8c4IkbbI7heDnbqz5g?key=74 t7

Figure 7 – Balance of the wallet (0x1Dd) that received funds from the hacker’s address 

You can view the wallet here 

The stolen funds were mostly from Optimism, Arbitrum, Ethereum and Binance smartchains, among others:

cccc

Figure 8 – Portfolio Value by Wallet Network (0x1Dd) 

Figure 8 – Portfolio value by wallet network (0x1Dd) according to ArbitrageScanner.io

Total loss due to hacker attack was ~$43M

Quotes on the BingX exchange

The most significant impact of the hack was on low liquidity tokens:

AD 4nXfBFJH0LUcdJP0FRh0AM9z nJaHpgFL4HiWBl0VJUb1qOpYV2mIkG4fqoJntJl89nOfT3pDOr0QguV84uL2WKIlDN35F75gFldkfxPUN02YTx8 p1lBwn9K 3EjZZ MD4JrOxcHHvnhoBY06UcWKzHQAZkMOdAgg7f 9wAJgYcsngiCT94CHxQ?key=74 t7

Figure 9 – Prices of low liquid tokens on the BingX exchange after the hacker attack

In the crypto market, hacks and attacks are a regular occurrence, and no major exchange is immune.

Examples include the incidents at OKX, which lost $140 million, and Binance, which lost $540 million. Such risks are inevitable, and companies build them into their security strategies.

That is why most reputable exchanges keep the majority of their reserves in cold wallets that are not accessible in the online environment, which significantly reduces the risk of theft.

Source: https://blockchainreporter.net/bingx-exchange-hacked-43-million-stolen-in-major-security-breach/