149 Million Credentials Exposed, With 420,000 Binance-Linked Accounts Affected

149 Million Credentials Exposed, With 420,000 Binance-Linked Accounts Affected

N
News Editor 01
2026-07-23 16:05:16
A security researcher uncovered an unprotected database containing about 149 million username-password pairs, including more than 420,000 linked to Binance users. Experts said the leak points to infostealer malware on user devices, not a breach of Binance’s systems.
Binancedata breachcybersecurityaccount securitymalware

An exposed database containing about 149 million username and password pairs has drawn attention across the security community, with roughly 420,000 records tied to Binance users. Security researcher Jeremiah Fowler said the dataset, totaling about 96GB, included credentials linked to services such as Gmail, Facebook, Instagram, Netflix, Outlook, iCloud, banking platforms, government services, dating apps, and Roblox.

An unprotected database left a massive credential trove searchable

The database was reportedly left without password protection or encryption, making the contents directly accessible to anyone who found it. Researchers described the collection as the kind of resource cybercriminals look for because it can be searched and sorted with little effort. Alongside the Binance-linked entries, the exposed set reportedly included around 48 million Gmail credentials and about 17 million Facebook credentials, showing how widely the records spanned daily online services.

Researchers point to infostealer malware on user devices

Experts said the incident does not indicate that Binance itself was hacked. Instead, the records appear to have been aggregated through infostealer malware that steals data from users’ own devices, including computers and phones. These programs are often disguised as game cheats, cracked software, or free utility tools. Once installed, they can collect saved browser passwords, cookies, and autofill data, then feed that information into large credential databases.

Credential stuffing is the immediate risk after leaks like this

The main threat, according to security specialists, is credential stuffing. Attackers take exposed login pairs and try them across multiple services at scale. Users who reuse the same password across exchanges, email accounts, and other websites face much greater exposure. For crypto users, that risk can become more serious because access to an email account may open a path to exchange account recovery or unauthorized login attempts.

Binance says its platform has no flaw and urges stronger account protection

Binance said its platform systems have no vulnerability tied to the incident. The exchange added that it is monitoring dark web activity and will notify affected users to help them reset passwords. Binance and security experts urged users to enable multi-factor authentication through hardware security keys or an authenticator app, rather than relying on SMS alone. They also recommended using a password manager for unique strong passwords, installing reputable anti-malware tools, running full device scans regularly, and avoiding suspicious links or unknown software downloads.

The leak puts the focus back on endpoint security. An exchange can protect its own infrastructure, but user devices and reused credentials remain a separate weak point.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.