Binance’s OTC desk posted exceptional activity in the first two months of 2026, with combined January and February volumes already reaching a quarter of the platform’s total for the entire 2025 year. Market observers attribute this surge to deepening institutional participation and a maturing market that demands larger, less disruptive trades.
CEO Richard Teng has noted that institutional clients increasingly seek deep liquidity through private block trades to minimize price impact and slippage. The OTC platform caters directly to this need, enabling large-volume executions away from the public order book. Binance, headquartered in Malta, serves both retail and professional investors globally. Teng, who took the helm in 2023, previously focused on regulatory compliance and now oversees the company’s rapid expansion in digital finance.
1.5 Million User Records Allegedly Leaked
Meanwhile, cybersecurity firm VECERT revealed that a hacker using the alias PexRat is selling a database containing information on 1.5 million Binance users. Leaked fields include full names, email addresses, phone numbers, KYC documents, last-login IPs, device fingerprints, and two-factor authentication (2FA) status. Such granular data could enable targeted social engineering attacks or SIM-swapping schemes.
VECERT’s investigation found no direct breach of Binance’s core servers. Instead, attackers appear to have executed credential stuffing attacks, exploiting client-side security gaps and bypassing or abusing Captcha mechanisms. According to the VECERT report: “The evidence suggests that the attacker managed to bypass or abuse security mechanisms (such as Captcha) in the login interface or some platform API, allowing a constant flow of unblocked requests.” Earlier this year, security researcher Jeremiah Fowler flagged 420,000 Binance-related credentials leaked via infostealer malware. The two incidents together intensify scrutiny over Binance’s data protection protocols.
Industry watchers say the situation tests Binance’s cybersecurity posture, as similar automated scraping and credential-stuffing attacks continue to erode user trust.

