A leaked dataset of 149M stolen credentials reportedly includes login details for around 420,000 Binance accounts.A leaked dataset of 149M stolen credentials reportedly includes login details for around 420,000 Binance accounts.

Attention Binance Users: Massive Malware Dataset Exposes 420,000 Accounts

3 min read

A trove of 149 million stolen credentials, including login details for 420,000 Binance accounts, was discovered circulating among cybercriminals this week.

The findings highlight a shift in crypto theft toward long-term malware infections that steal data directly from users’ devices, often long before any funds are moved.

The Scale of the Threat

According to an alert posted on February 4 by security firm Web3 Antivirus, the dataset was compiled from information-stealing malware installed on victim devices. Beyond exchange logins, the stolen data included passwords, private keys, API keys, and browser session tokens for email, social, and financial platforms.

The firm noted that these “infostealers” capture data that can later be used for account takeovers and fund theft, emphasizing that prevention requires early detection at the device level since by the time suspicious activity appears on-chain, it is often too late.

Furthermore, in a separate series of posts, Web3 Antivirus detailed how malicious AI skills on platforms like ClawHub are being used to steal crypto data. Per the security firm, these fraudulent skills, posing as wallet tools or trading bots, install information-stealing malware that can remain dormant until a victim’s crypto balance grows or specific actions are taken. This vulnerability represents a supply-chain risk that moves upstream “from wallets to the tools people trust to manage them.”

A Persistent Challenge for Users and Platforms

The gravity of losses resulting from crypto theft cannot be understated. A recent report from PeckShield noted that scams and hacks drained over $4.04 billion in 2025, with scams alone jumping 64% year-over-year. The firm observed a move toward targeting centralized exchanges and large organizations, which accounted for 75% of stolen funds in 2025.

Meanwhile, Web3 Antivirus put the volume of 2025’s illicit crypto activity at approximately $158 billion, up from $64 billion in 2024. While the on-chain security provider partly attributed the increase to better tracking and more state-linked activity, the figures show that even small success rates for thieves can result in large losses at scale.

The recent data thefts highlighted a gap between user and platform protection, with the company stating,

The firm argued that platforms, which can see transaction approvals and behavioral patterns before users do, sit at “the last real control point” for preventing theft.

One of the more common attack vectors is wallet drainers, which Web3 Antivirus stated had gotten worse, with 15,530 suspicious approvals across 11,908 wallets leading to $4.25 million in losses in January. These drainers usually enter through malicious transaction approvals, making pre-signature detection extremely important.

The post Attention Binance Users: Massive Malware Dataset Exposes 420,000 Accounts appeared first on CryptoPotato.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRP Enters ‘Washout Zone,’ Then Targets $30, Crypto Analyst Says

XRP Enters ‘Washout Zone,’ Then Targets $30, Crypto Analyst Says

XRP has entered what Korean Certified Elliott Wave Analyst XForceGlobal (@XForceGlobal) calls a “washout” phase inside a broader Elliott Wave corrective structure
Share
NewsBTC2026/02/05 08:00
Republicans are 'very concerned about Texas' turning blue: GOP senator

Republicans are 'very concerned about Texas' turning blue: GOP senator

While Republicans in the U.S. House of Representatives have a razor-thin with just a four-seat advantage, their six-seat advantage in the U.S. Senate is seen as
Share
Alternet2026/02/05 08:38
Headwind Helps Best Wallet Token

Headwind Helps Best Wallet Token

The post Headwind Helps Best Wallet Token appeared on BitcoinEthereumNews.com. Google has announced the launch of a new open-source protocol called Agent Payments Protocol (AP2) in partnership with Coinbase, the Ethereum Foundation, and 60 other organizations. This allows AI agents to make payments on behalf of users using various methods such as real-time bank transfers, credit and debit cards, and, most importantly, stablecoins. Let’s explore in detail what this could mean for the broader cryptocurrency markets, and also highlight a presale crypto (Best Wallet Token) that could explode as a result of this development. Google’s Push for Stablecoins Agent Payments Protocol (AP2) uses digital contracts known as ‘Intent Mandates’ and ‘Verifiable Credentials’ to ensure that AI agents undertake only those payments authorized by the user. Mandates, by the way, are cryptographically signed, tamper-proof digital contracts that act as verifiable proof of a user’s instruction. For example, let’s say you instruct an AI agent to never spend more than $200 in a single transaction. This instruction is written into an Intent Mandate, which serves as a digital contract. Now, whenever the AI agent tries to make a payment, it must present this mandate as proof of authorization, which will then be verified via the AP2 protocol. Alongside this, Google has also launched the A2A x402 extension to accelerate support for the Web3 ecosystem. This production-ready solution enables agent-based crypto payments and will help reshape the growth of cryptocurrency integration within the AP2 protocol. Google’s inclusion of stablecoins in AP2 is a massive vote of confidence in dollar-pegged cryptocurrencies and a huge step toward making them a mainstream payment option. This widens stablecoin usage beyond trading and speculation, positioning them at the center of the consumption economy. The recent enactment of the GENIUS Act in the U.S. gives stablecoins more structure and legal support. Imagine paying for things like data crawls, per-task…
Share
BitcoinEthereumNews2025/09/18 01:27