The post Binance CEO had WeChat hacked by cellphone exploit that likely leaves your own crypto exposed appeared on BitcoinEthereumNews.com. Binance co-CEO Yi He said her WeChat account was hijacked on Dec. 10 after a cell number tied to the profile was reclaimed and could not be recovered at first. The account was later restored after Binance worked with WeChat’s security team, according to a spokesperson cited the same day. Posts that appeared after the takeover promoted a token called “Mubarakah,” and on-chain data shared by Lookonchain pointed to a pump-and-dump that netted about $55,000 before the content was removed. Why Yi He’s WeChat hack matters beyond Binance The episode arrived days after Yi He’s elevation to co-CEO was announced at Binance Blockchain Week, placing an executive’s identity at the center of a web platform incident rather than a crypto infrastructure breach. Web accounts tied to phone numbers remain exposed to recovery flows that attackers can capture without touching wallets, custody systems, or exchange backends, a pattern that has shaped several market-moving incidents over the past two years. According to the SEC’s postmortem on its January 2024 X compromise, a phone number on the agency’s account lacked two-factor protection, and a fake ETF-approval post briefly moved Bitcoin by roughly $1,000 before corrections followed. The SEC and FBI later detailed arrests linked to that hack. According to the SEC document, that case has become a reference point for how a single spoofed message can reshape price action and trigger liquidations without any on-chain exploit. SlowMist’s founder resurfaced guidance last week describing how WeChat account captures can proceed with leaked credentials and “frequent contacts” verification. That method can advance recovery by messaging two contacts to satisfy identity checks, creating a low-friction path for attackers. According to City News Service in Shanghai, Chinese carriers typically reissue canceled numbers after around 90 days, a secondary issuance practice that intersects with legacy SMS recovery and leaves… The post Binance CEO had WeChat hacked by cellphone exploit that likely leaves your own crypto exposed appeared on BitcoinEthereumNews.com. Binance co-CEO Yi He said her WeChat account was hijacked on Dec. 10 after a cell number tied to the profile was reclaimed and could not be recovered at first. The account was later restored after Binance worked with WeChat’s security team, according to a spokesperson cited the same day. Posts that appeared after the takeover promoted a token called “Mubarakah,” and on-chain data shared by Lookonchain pointed to a pump-and-dump that netted about $55,000 before the content was removed. Why Yi He’s WeChat hack matters beyond Binance The episode arrived days after Yi He’s elevation to co-CEO was announced at Binance Blockchain Week, placing an executive’s identity at the center of a web platform incident rather than a crypto infrastructure breach. Web accounts tied to phone numbers remain exposed to recovery flows that attackers can capture without touching wallets, custody systems, or exchange backends, a pattern that has shaped several market-moving incidents over the past two years. According to the SEC’s postmortem on its January 2024 X compromise, a phone number on the agency’s account lacked two-factor protection, and a fake ETF-approval post briefly moved Bitcoin by roughly $1,000 before corrections followed. The SEC and FBI later detailed arrests linked to that hack. According to the SEC document, that case has become a reference point for how a single spoofed message can reshape price action and trigger liquidations without any on-chain exploit. SlowMist’s founder resurfaced guidance last week describing how WeChat account captures can proceed with leaked credentials and “frequent contacts” verification. That method can advance recovery by messaging two contacts to satisfy identity checks, creating a low-friction path for attackers. According to City News Service in Shanghai, Chinese carriers typically reissue canceled numbers after around 90 days, a secondary issuance practice that intersects with legacy SMS recovery and leaves…

Binance CEO had WeChat hacked by cellphone exploit that likely leaves your own crypto exposed

2025/12/11 05:15

Binance co-CEO Yi He said her WeChat account was hijacked on Dec. 10 after a cell number tied to the profile was reclaimed and could not be recovered at first.

The account was later restored after Binance worked with WeChat’s security team, according to a spokesperson cited the same day.

Posts that appeared after the takeover promoted a token called “Mubarakah,” and on-chain data shared by Lookonchain pointed to a pump-and-dump that netted about $55,000 before the content was removed.

Why Yi He’s WeChat hack matters beyond Binance

The episode arrived days after Yi He’s elevation to co-CEO was announced at Binance Blockchain Week, placing an executive’s identity at the center of a web platform incident rather than a crypto infrastructure breach.

Web accounts tied to phone numbers remain exposed to recovery flows that attackers can capture without touching wallets, custody systems, or exchange backends, a pattern that has shaped several market-moving incidents over the past two years.

According to the SEC’s postmortem on its January 2024 X compromise, a phone number on the agency’s account lacked two-factor protection, and a fake ETF-approval post briefly moved Bitcoin by roughly $1,000 before corrections followed. The SEC and FBI later detailed arrests linked to that hack.

According to the SEC document, that case has become a reference point for how a single spoofed message can reshape price action and trigger liquidations without any on-chain exploit.

SlowMist’s founder resurfaced guidance last week describing how WeChat account captures can proceed with leaked credentials and “frequent contacts” verification. That method can advance recovery by messaging two contacts to satisfy identity checks, creating a low-friction path for attackers.

According to City News Service in Shanghai, Chinese carriers typically reissue canceled numbers after around 90 days, a secondary issuance practice that intersects with legacy SMS recovery and leaves dormant accounts exposed when numbers are recycled.

If an old number remains tied to an abandoned profile, a new holder can receive SMS prompts or meet recovery checks that either bypass or weaken password reliance, which aligns with Yi He’s account that the number linked to her profile “was seized for use.”

WeChat’s role in crypto circles raises conversion risk when executive or key opinion leader accounts are hijacked. Many OTC USDT trades and retail community discussions run through the app, and a familiar handle can convey enough implied trust to draw flows into thin-liquidity contracts.

That dynamic differs from a random spam link on X, where user overlap and transaction intent may be lower.

Binance’s own ecosystem has encountered social-account risk this year, with BNB Chain’s official X account compromised on Oct. 1, ten phishing links posted, and about $8,000 in user losses later reimbursed.

The immediate market impact around Yi He’s WeChat case appeared contained. As of Dec. 10 in London trading hours, BNB was roughly flat on the day near $890, with intraday highs and lows ranging between $927.32 and $884.67.

TickerPrice (USD)Δ vs prior closeIntraday highIntraday low
BNB890.17-9.02 (-0.01%)927.32884.67

The economic payoff cited in this incident, approximately $55,000, fits a lower band for single-push memecoin shills. Coordinated hijacks across multiple X accounts have cleared around $500,000 in a month by repeatedly directing retail into new tokens.

A simple reach-to-revenue illustration helps frame incentives

As a model, if a hijacked executive account reaches 1 to 5 million contacts, if 0.05% to 0.20% click through, and if 10% of those clickers deploy $100 each into a shallow pool, gross inflows would span about $5,000–$100,000 per post, consistent with the $55,000 estimate.

While this is a model, not a statement of fact, it aligns with observed outcomes when an identity carries audience trust and the token’s liquidity is thin.

Rising loss totals across 2024 provide the macro backdrop. Chainalysis and TRM Labs estimate roughly $2.2 billion in stolen crypto this year, with a midyear pivot toward attacks on centralized services, even as the share of illicit activity on-chain remains under 1%.

Sanctioned entities are leaning more on stablecoins, according to Chainalysis and TRM Labs, which keeps policy attention on operational and identity risks that can be exploited without cracking cryptography. The policy response is shifting, too.

South Korea moved on Nov. 27 toward “bank-level” no-fault liability for exchanges after the Upbit incident, creating a possible blueprint for how regulators may assign responsibility for platform-adjacent losses that involve social engineering or third-party platform weaknesses.

The security mechanics in Yi He’s case highlight where controls can fail

SIM recycling plus social recovery allows takeovers when a platform accepts SMS or contact-based proofs over hardware-bound factors. “Frequent contacts” verification accelerates capture by co-opting social ties, especially when contacts are accustomed to authorizing routine actions.

If an executive account is dormant, device fingerprints and session recency may be stale, making it easier for a recycled number to pass recovery gates.

According to Binance security alerts published earlier this year, attackers have repeatedly tested WeChat-centric flows that combine leaked credentials, contact verification, and number reuse.

For boards and compliance teams, executive identities now function like market infrastructure. A single unvetted post can mobilize nine-figure volume, lead to user losses, and force public remediation. That governance perimeter sits outside exchange custody and traditional cybersecurity budgets.

It spans personal devices, legacy accounts, carrier policies, and third-party platform settings, which complicates control audits and disclosure protocols.

The SEC X incident, the BNB Chain account compromise, and ongoing celebrity memecoin hijacks reported by media like WIRED show that social-account security is a repeatable route to market impact.

Given the facts to date, forward paths fall into three bands

A contained reputational blip would involve no further impostor posts, a short platform note from Binance, no user losses beyond the attacker’s take, and limited BNB or broader Binance market impact.

A policy ripple with limited market stress would see APAC or European authorities issue guidance on executive social-account governance, possibly leaning on South Korea’s direction, with hardware-key mandates and no-fault compensation standards for verified social-engineered incidents.

An escalation to a market-moving spoof would target a listing or airdrop claim, coordinate across channels, and push nine-figure volume before takedown, echoing the SEC precedent and prior cross-account hijacks.

Signposts include new phishing domains or wallet clusters tied to known scam infrastructure, enterprise attestations of web account controls, and WeChat statements on recycled-number remediation.

Risk-reducing measures are well mapped. A kill-switch policy for executive accounts not used for business, phone, or SMS recovery, disabled; hardware keys enforced; and organization SSO for any channel that could be construed as corporate communication would cut exposure.

Platform-side, WeChat could require recent successful device-bound logins before allowing broadcast-scale posting from public-figure accounts linked to recycled numbers, and expand enterprise-grade verification for high-reach handles.

Those measures would not eliminate spoofing, but they would reduce the likelihood and shorten the window during which a hijack can monetize an audience.

Open items remain. It is not yet clear whether Binance users suffered direct losses from links posted on WeChat and whether any restitution will be offered for off-platform harm.

It is also unknown whether secondary channels amplified the “Mubarakah” posts or whether WeChat’s internal network effects contained the impact.

Confirmation of the token’s chain and contracts, and any coordination between centralized venues and DEX front ends to flag or block trading, would clarify the operational footprint.

Yi He’s account has been restored, according to Binance, and attention now shifts to whether carriers and WeChat adjust safeguards around recycled numbers and contact-based recovery.

Mentioned in this article

Source: https://cryptoslate.com/binance-co-ceo-lost-her-wechat-to-cellphone-loophole-that-likely-leaves-your-own-crypto-exposed/

Piyasa Fırsatı
Cellframe Logosu
Cellframe Fiyatı(CELL)
$0,1291
$0,1291$0,1291
-3,29%
USD
Cellframe (CELL) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Trump-Backed WLFI Plunges 58% – Buyback Plan Announced to Halt Freefall

Trump-Backed WLFI Plunges 58% – Buyback Plan Announced to Halt Freefall

World Liberty Financial (WLFI), the Trump-linked DeFi project, is scrambling to stop a market collapse after its token lost over 50% of its value in September. On Friday, the project unveiled a full buyback-and-burn program, directing all treasury liquidity fees to absorb selling pressure. According to a governance post on X, the community approved the plan overwhelmingly, with WLFI pledging full transparency for every burn. The urgency of the move reflects WLFI’s steep losses in recent weeks. WLFI is trading Friday at $0.19, down from its September 1 peak of $0.46, according to CoinMarketCap, a 58% drop in less than a month. Weekly losses stand at 12.85%, with a 15.45% decline for the month. This isn’t the project’s first attempt at intervention. Just days after launch, WLFI burned 47 million tokens on September 3 to counter a 31% sell-off, sending the supply to a verified burn address. For World Liberty Financial, the buyback-and-burn program represents both a damage-control measure and a test of community faith. While tokenomics adjustments can provide short-term relief, the project will need to convince investors that WLFI has staying power beyond interventions. WLFI Launches Buyback-and-Burn Plan, Linking Token Scarcity to Platform Growth According to the governance proposal, WLFI will use fees generated from its protocol-owned liquidity (POL) pools on Ethereum, BNB Chain, and Solana to repurchase tokens from the open market. Once bought back, the tokens will be sent to a burn address, permanently removing them from circulation.WLFI Proposal Source: WLFI The project stressed that this system ties supply reduction directly to platform growth. As trading activity rises, more liquidity fees are generated, fueling larger buybacks and burns. This seeks to create a feedback loop where adoption drives scarcity, and scarcity strengthens token value. Importantly, the plan applies only to WLFI’s protocol-controlled liquidity pools. Community and third-party liquidity pools remain unaffected, ensuring the mechanism doesn’t interfere with external ecosystem contributions. In its proposal, the WLFI team argued that the strategy aligns long-term holders with the project’s future by systematically reducing supply and discouraging short-term speculation. Each burn increases the relative stake of committed investors, reinforcing confidence in WLFI’s tokenomics. To bolster credibility, WLFI has pledged full transparency: every buyback and burn will be verifiable on-chain and reported to the community in real time. WLFI Joins Hyperliquid, Jupiter, and Sky as Buyback Craze Spills Into Wall Street WLFI’s decision to adopt a full buyback-and-burn strategy places it among the most ambitious tokenomic models in crypto. While partly a response to its sharp September price decline, the move also reflects a trend of DeFi protocols leveraging revenue streams to cut supply, align incentives, and strengthen token value. Hyperliquid illustrates the model at scale. Nearly all of its platform fees are funneled into automated $HYPE buybacks via its Assistance Fund, creating sustained demand. By mid-2025, more than 20 million tokens had been repurchased, with nearly 30 million held by Q3, worth over $1.5 billion. This consistency both increased scarcity and cemented Hyperliquid’s dominance in decentralized derivatives. Other protocols have adopted variations. Jupiter directs half its fees into $JUP repurchases, locking tokens for three years. Raydium earmarks 12% of fees for $RAY buybacks, already removing 71 million tokens, roughly a quarter of the circulating supply. Burn-based models push further, as seen with Sky, which has spent $75 million since February 2025 to permanently erase $SKY tokens, boosting scarcity and governance influence. But the buyback phenomenon isn’t limited to DeFi. Increasingly, listed companies with crypto treasuries are adopting aggressive repurchase programs, sometimes to offset losses as their digital assets decline. According to a report, at least seven firms, ranging from gaming to biotech, have turned to buybacks, often funded by debt, to prop up falling stock prices. One of the latest is Thumzup Media, a digital advertising company with a growing Web3 footprint. On Thursday, it launched a $10 million share repurchase plan, extending its capital return strategy through 2026, after completing a $1 million program that saw 212,432 shares bought at an average of $4.71. DeFi Development Corp, the first public company built around a Solana-based treasury strategy, also recently expanded its buyback program to $100 million, up from $1 million, making it one of the largest stock repurchase initiatives in the digital asset sector. Together, these cases show how buybacks, whether in tokenomics or equities, are emerging as a key mechanism for stabilizing value and signaling confidence, even as motivations and execution vary widely
Paylaş
CryptoNews2025/09/26 19:12
Son of filmmaker Rob Reiner charged with homicide for death of his parents

Son of filmmaker Rob Reiner charged with homicide for death of his parents

FILE PHOTO: Rob Reiner, director of "The Princess Bride," arrives for a special 25th anniversary viewing of the film during the New York Film Festival in New York
Paylaş
Rappler2025/12/16 09:59
Bitcoin Peak Coming in 45 Days? BTC Price To Reach $150K

Bitcoin Peak Coming in 45 Days? BTC Price To Reach $150K

The post Bitcoin Peak Coming in 45 Days? BTC Price To Reach $150K appeared first on Coinpedia Fintech News Bitcoin has delivered one of its strongest performances in recent months, jumping from September lows of $108K to over $117K today. But while excitement is high, market watchers warn the clock is ticking.  History shows Bitcoin peaks don’t last forever, and analysts now believe the next major top could arrive within just 45 days, with …
Paylaş
CoinPedia2025/09/18 15:49