Market Cap: $2.2006T 0.50%
Volume(24h): $37.9391B -38.27%
  • Market Cap: $2.2006T 0.50%
  • Volume(24h): $37.9391B -38.27%
  • Fear & Greed Index:
  • Market Cap: $2.2006T 0.50%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

Cryptocurrency News Articles

Chinese trader loses $1 million in Binance hacking scam

Jun 04, 2024 at 05:20 am

A Chinese trader lost $1 million after falling victim to a hacking scam involving a promotional Google Chrome plugin called Aggr.

Chinese trader loses $1 million in Binance hacking scam

A Chinese cryptocurrency trader has lost $1 million in a hacking scam perpetrated through a promotional Google Chrome plugin called Aggr. The plugin reportedly stole cookies from users, enabling hackers to bypass password and two-factor authentication (2FA) verification to access the victim’s Binance account.

The trader, who goes by the handle CryptoNakamao on social media platform X, recounted the incident, which occurred on May 24. He noticed unusual trading activity in his Binance account after checking the Bitcoin price on the Binance app. By the time he sought assistance, the hacker had already withdrawn all the funds.

The trader claimed that the hackers accessed his web browser cookie data through the Aggr Chrome plugin. He had installed the plugin to gain insights from prominent traders, unaware that it was designed to steal browsing data and cookies. The hackers used the stolen cookies to hijack active user sessions without needing passwords or authentication, enabling them to carry out multiple leveraged trades and profit by manipulating low liquidity trading pairs.

Despite the hacker's inability to directly withdraw funds due to 2FA, they used the cookies and active login sessions to execute trades. The hacker bought several tokens in the Tether (USDT) trading pair with high liquidity and placed limit sell orders at inflated prices in Bitcoin (BTC), USD Coin (USDC), and other low liquidity trading pairs. They then opened leveraged positions, bought large amounts, and completed cross-trading. Cross-trading involves offsetting buy and sell orders for the same asset without recording the trade on the exchange.

Accusations Against Binance

The trader accused Binance of failing to implement necessary security measures despite the unusually high trading activity on his account. He also claimed that the exchange did not take timely action even after he reported the issue. According to the trader, Binance was aware of the fraudulent plugin and was conducting an internal investigation but did not inform users or take preventive measures.

“Binance did nothing even though it knew of the theft and frequent cross-trading. Hackers manipulated accounts for over an hour, causing extremely abnormal transactions in multiple currency pairs without any risk control; Binance failed to freeze the funds of the obvious hacker’s single account on the platform in time,” the trader wrote.

Binance’s Response

Yi He, co-founder of Binance, refuted CryptoNakamao's claims and clarified the situation on social media, stating, “Look closely; this user's account was breached because their own computer was hacked; they are a lost cause. After the hack, the hacker could not withdraw funds, so the hacker sold the victim’s coins, which led to trading losses.”

“We sympathize with your experience, but according to the information we have learned so far, the reason for your asset loss is that your related devices were manipulated because of the installation of malicious plug-ins. Unfortunately, we have no way to compensate for such cases that have nothing to do with Binance,” the exchange stated.

Nakamao, however, disputed Binance's assessment, alleging that the exchange had been aware of the malicious plugin for some time and had even encouraged a key opinion leader (KOL) to gather more information from the hacker.

On her part, Yi He warned users about the dangers of logging into accounts with active cookie plugins to avoid the inconvenience of typing their passwords each time. “Binance is not able to compensate users when their own login devices are compromised,” she stated.

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Jul 26, 2026