Binance has issued a warning about a malware attack targeting its users, which alters cryptocurrency withdrawal addresses.
The malware replaces a user’s intended withdrawal address with that of the scammer, leading to irreversible financial losses if the user does not notice the change before completing the transaction.
Since August 2024, this sophisticated malware has been spreading, with attackers using it to divert funds to their wallets. Binance’s security team is actively blocking and reporting these malicious addresses and alerting affected users. They are also blacklisting suspicious addresses and coordinating with law enforcement.
Users are advised to exercise extreme caution when downloading applications or browser extensions, particularly from unofficial sources, and to double-check withdrawal addresses. Binance suggests taking screenshots of wallet addresses before confirming transactions as an additional safeguard.
Additionally, a fraudulent website pretending to offer help with the malware issue has emerged. This site, which misuses Binance’s branding, attempts to trick users into granting unauthorized access to their wallets. Binance emphasizes that these scammers exploit victims already affected by the malware, highlighting the importance of vigilance against such deceptive schemes.
The U.S. Department of Justice has sentenced Dwayne Golden, 57, of Pennsylvania to 97 months in prison for orchestrating a fraudulent crypto investment scheme that stole over $40 million from investors.
The first half of 2025 has become the most damaging six-month period in crypto history, with over $2.1 billion stolen across 75+ separate incidents, according to new data.
A new breed of cyber-attack is sweeping through crypto media, exploiting site pop-ups and wallet-connect prompts instead of smart-contract bugs.
CoinMarketCap, one of the most widely used crypto data tracking platforms, is reportedly facing a front-end security breach, with multiple users encountering a suspicious prompt to verify their wallets.