简体中文
繁體中文
English
Pусский
日本語
ภาษาไทย
Tiếng Việt
Bahasa Indonesia
Español
हिन्दी
Filippiiniläinen
Français
Deutsch
Português
Türkçe
한국어
العربية
Abstract:A Chinese trader fell prey to a sophisticated hacking scam on Binance, losing $1 million after hackers exploited a deceptive Chrome plugin, Aggr, to bypass security measures, execute leveraged trades, and manipulate low liquidity trading pairs, raising questions about Binance's security protocols and responsibility for compensating such losses.
A significant financial loss has befallen a Chinese trader, totalling $1 million, due to a deceitful scheme involving a promotional Google Chrome extension named Aggr.
The plugin, Aggr, reportedly extracted cookies from users, granting hackers access to bypass password and two-factor authentication (2FA) protocols, thus breaching the traders Binance account.
The incident, narrated by the trader under the pseudonym CryptoNakamao on the social media platform X, transpired on May 24. Upon checking the Bitcoin price through the Binance app, the trader detected peculiar trading activities within their account. Regrettably, by the time they sought assistance, the entirety of their funds had been withdrawn by the hacker.
The trader disclosed that the hackers infiltrated his web browsers cookie data through the Aggr Chrome extension. Initially installed for gaining insights from notable traders, the trader remained oblivious to its covert function of pilfering browsing data and cookies. Leveraging the stolen cookies, the hackers seized active user sessions, circumventing the necessity for passwords or authentication. This enabled them to execute numerous leveraged trades and exploit low liquidity trading pairs for profit.
Despite the hindrance of 2FA preventing direct fund withdrawals, the hackers utilized the cookies and active login sessions to engage in trading activities. Employing high liquidity tokens in the Tether (USDT) trading pair, the hackers placed limit sell orders at inflated prices across Bitcoin (BTC), USD Coin (USDC), and other trading pairs with low liquidity. Subsequently, they initiated leveraged positions, acquiring substantial amounts, and executed cross-trading manoeuvres, a tactic involving the offsetting of buy and sell orders for the same asset without recording the transaction on the exchange.
The trader levelled accusations against Binance, alleging a deficiency in implementing requisite security measures, especially considering the abnormal trading activities observed. Furthermore, the trader asserted that despite reporting the issue promptly, Binance failed to take timely action. According to the trader, Binance was already cognizant of the fraudulent nature of the plugin, yet failed to notify users or enact preventative measures.
In response, Yi He, co-founder of Binance, refuted CryptoNakamao‘s claims, attributing the account breach to the compromised state of the user’s own computer. Yi He clarified on social media that following the hack, the hacker was unable to withdraw funds, resulting in trading losses upon the sale of the victims coins.
Expressing sympathy for the trader's ordeal, Binance reiterated its stance, indicating that the cause of asset loss stemmed from the manipulation of the traders devices due to the installation of malicious plugins. Consequently, Binance disclaimed responsibility for compensating such instances unrelated to its platform.
Disagreeing with Binances assessment, Nakamao contended that the exchange had prior knowledge of the malicious plugin and had even encouraged a key opinion leader (KOL) to gather intelligence from the hacker.
In a cautionary note, Yi He advised users against logging into accounts with active cookie plugins to avert the inconvenience of repeated password entries. She emphasized Binances inability to provide compensation in instances of compromised login devices.
Disclaimer:
The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.
On 12th November, a crypto investor fell victim to a sophisticated phishing attack, losing $6 million worth of GigaChad (GIGA) tokens.
Italy and Denmark are rethinking how to tax digital assets. Italy’s government, initially proposing a substantial capital gains tax increase on crypto to 42%, has decided to lower this figure to 28%. Meanwhile, Denmark is advancing a different strategy by recommending a mark-to-market taxation model, which would impose taxes on crypto based on annual value changes rather than sale or exchange events.
Bitget, one of the largest crypto exchanges, returns to the UK market with full regulatory Compliance, offering access to over 150 cryptocurrencies.
Amid ongoing efforts to recover assets for creditors of the defunct crypto exchange FTX, Sam Trabucco, former co-CEO of Alameda Research, has agreed to forfeit high-value assets, including two San Francisco properties and a yacht. According to a court filing dated 3 November, the combined value of these assets reaches approximately $11.2 million — with the properties estimated at $8.7 million and the 53-foot yacht at $2.5 million.