Key Takeaways:
- BNB Chain’s official X account was compromised and used to share phishing links, leading to an estimated $8,000 in user losses.
- The attack was linked to the Inferno Drainer group and used lookalike domains to trick users into connecting wallets.
- Control of the account has been restored; BNB Chain pledged to reimburse affected users and improve internal security.
BNB Chain’s official X account was compromised in a phishing attack on Wednesday, with hackers posting deceptive links disguised as Wallet Connect prompts.
Binance founder Changpeng “CZ” Zhao confirmed the breach, warning users: “Do NOT connect your wallet.”
ALERT 🚨: The @BNBCHAIN X account is compromised.
— CZ 🔶 BNB (@cz_binance) October 1, 2025
The hacker posted a bunch of links to phishing websites that ask for Wallet Connect.
Do NOT connect your wallet.
Security teams have notified X already, working to suspend the account first, then restore access.
Also take-down… https://t.co/QeEnCCbFZe
The phishing links, later traced to the Inferno Drainer group, tricked users with lookalike domains, swapping characters like “i” with “l.”
According to SlowMist’s CISO, the attackers employed classic tactics linked to phishing-as-a-service operations.
Security teams moved quickly to suspend the account and issue takedown requests.
As of Thursday, control of the X account has been fully restored.
X account restored. Hacker got $13k.
— CZ 🔶 BNB (@cz_binance) October 1, 2025
Security team(s) still tracking, with a possible linked KYC. Hacker went through all these trouble, plus criminal liability. He could have made more by building.
Victims will be compensated in full.
Social media security is not the same as… https://t.co/rVYK1NRguz
Estimates of the stolen funds vary, with reports citing losses between $8,000 and $13,000.
BNB Chain stated that all affected users will be reimbursed in full.
CZ reiterated the importance of vigilance, urging users to double-check domains even from verified accounts: “Stay SAFU!”
The breach highlights the growing threat of social engineering attacks on official crypto accounts and has prompted renewed scrutiny over security practices in the space.