Hackers Reportedly Leak 1.5 Million Binance Account Login Data
Hackers have compromised login credentials for 1.5 million Binance users through a sophisticated captcha-bypass attack, exposing email addresses, phone numbers, and two-factor authentication details that create immediate SIM-swap and phishing risks. For institutional investors using Binance’s growing OTC platform, which processed 25% of its annual 2025 volume in just January and February, the incident underscores operational security gaps that could threaten the exchange’s credibility as a custodian of large-scale institutional capital.
- Threat actor PexRat offered 1.5 million Binance user records for sale on March 28, including names, emails, and 2FA status information.
- Binance’s OTC desk processed 25% of its total 2025 annual volume in January and February alone, signaling institutional momentum.
- Attack bypassed captcha controls via credential stuffing rather than direct server breach, leaving users vulnerable to SIM-swap and phishing campaigns.
- 1.5M Binance users affected by data leak versus 420,000 from January infostealer incident
- 25% OTC volume in two months versus full 2025 annual baseline
- March 28 Date threat actor PexRat disclosed sale of compromised credentials database
Binance entered 2026 as a study in institutional divergence. The world’s largest cryptocurrency exchange by market capitalization is accelerating its push into institutional over-the-counter trading, capitalizing on demand from large-cap investors seeking deep liquidity for block trades without public market disruption.
Yet simultaneously, the platform faces an escalating pattern of credential compromise at the retail level, a vulnerability that regulators, institutional clients, and enterprise risk officers cannot ignore.
On March 28, cybersecurity platform VECERT disclosed that a threat actor operating under the alias PexRat had placed a database containing personal information on 1.5 million Binance users up for sale. The compromised dataset purportedly includes full names, email addresses, phone numbers, and Know Your Customer verification statuses.
Beyond identity information, the threat actor claims access to more sensitive operational data: last-login IP addresses, device user agents, and complete two-factor authentication status details, including whether victims use SMS, email, or dedicated authenticator apps.
The exposure of 2FA infrastructure and KYC data creates a direct operational vulnerability.
Compromised users now face heightened risk of SIM-swap attacks, in which adversaries hijack phone numbers tied to accounts, and sophisticated phishing campaigns targeting authenticated sessions. The combination of confirmed identity details, phone numbers, and knowledge of authentication methods creates a layered attack surface that extends well beyond simple credential theft.
Captcha Bypass Attack Reveals Systematic Scraping Rather Than Server Breach
VECERT’s technical analysis of the leaked data and authentication logs produced a critical finding: Binance’s internal servers were not directly breached. Instead, the incident stemmed from a sustained automated scraping operation that systematically exploited or bypassed the exchange’s login security controls.
The cybersecurity firm outlined the attack methodology with precision: “The evidence suggests that the attacker managed to bypass or abuse security mechanisms (such as Captcha) in the login interface or some platform API, allowing a constant flow of unblocked requests.”
This credential stuffing and scraping campaign likely leveraged previously compromised username and password combinations from other data breaches, then automated repeated login attempts against Binance accounts.
Once successful logins were identified, the attacker harvested not only confirmation of valid credentials but also the associated metadata: user agent strings, IP addresses from last-login events, and authentication method configurations stored within Binance’s systems.
The attack method signals a gap in Binance’s rate-limiting and bot-detection infrastructure.
The fact that an attacker could sustain high-volume automated requests long enough to compromise 1.5 million accounts suggests that Binance’s defenses against distributed or sophisticated scraping attacks, such as behavioral analysis, machine learning-based anomaly detection, or aggressive account lockout policies following repeated failed logins, either failed or were insufficient.
This incident follows a January 2026 report by cybersecurity researcher Jeremiah Fowler, who uncovered approximately 420,000 Binance-linked credentials exposed through infostealer malware, a separate but related threat vector showing ongoing pressure on user account security across the platform.
Institutional OTC Momentum Collides With Retail Security Failures
The timing of this breach creates a critical narrative tension for Binance’s business trajectory.
CEO Richard Teng has publicly positioned the exchange’s OTC platform as a cornerstone of institutional growth, emphasizing that large-cap investors and institutional players increasingly demand direct execution channels to achieve deep liquidity and avoid market disruption from public order book activity.
Binance’s OTC desk performance validates that strategy: in January and February 2026 alone, the platform processed 25% of its total volume for the entire preceding year, an extraordinary concentration that reflects genuine institutional appetite.
However, institutional capital flows to exchanges that can credibly manage operational risk and data security. Large asset managers, hedge funds, and pension funds conduct due diligence on platform security infrastructure before committing significant capital.
A sustained pattern of account compromises, now encompassing 1.5 million users in March plus 420,000 in January, creates a reputational and operational risk narrative that contradicts Binance’s institutional positioning.
Institutional investors must now weigh the exchange’s market liquidity and OTC capabilities against escalating evidence that its core authentication and bot-detection systems are under systematic pressure.
If additional breaches occur or if the March incident leads to regulatory scrutiny in jurisdictions where Binance operates major OTC desks, the exchange could face restrictions on large-value transactions, enhanced AML monitoring requirements, or demands for third-party security audits that disrupt operational efficiency.
Unresolved Questions on Account Recovery and Incident Response Timeline
Binance has not publicly disclosed what actions it has taken to mitigate the exposure for affected users or to remediate the captcha bypass vulnerability. The exchange has not announced mandatory password resets for compromised accounts, enforcement of new authentication requirements, or proactive notifications to the 1.5 million users identified in the breach.
This silence creates operational uncertainty for institutional participants who may rely on Binance infrastructure for enterprise client accounts or custody relationships.
A critical open question remains whether Binance’s incident response to the March breach will differ substantively from previous compromises. If the platform relies solely on public disclosure by third-party researchers rather than proactive notification and security improvements, the underlying infrastructure gaps, particularly in rate-limiting and bot detection, will likely persist.
Institutional investors considering large OTC transactions through Binance should seek clarity on whether the exchange has engaged external security auditors, implemented new controls, or established timelines for vulnerability remediation.
Binance’s next public statement on the March 28 breach, either a formal security advisory, disclosure of remediation steps, or regulatory filing, will determine whether institutional confidence in the platform stabilizes or erodes further. Simultaneously, VECERT and other cybersecurity firms will likely release additional technical analysis of the attack methodology, which could reveal whether the captcha bypass affects other major exchanges using similar login infrastructure. The exchange cannot afford repeated public incidents without demonstrating measurable improvements to account security, particularly as it seeks to expand institutional OTC volume in a regulatory environment increasingly focused on custody and platform resilience standards.
