420,000 Binance-Linked Credentials Found In Massive 149M Record Data Leak

Bitcoin 2026-01-28 02:50

420,000 Binance-Linked Credentials Found In Massive 149M Record Data Leak

Roughly 420,000 records referencing Binance accounts were found among 149 million exposed logins and passwords in a massive unprotected database uncovered by cybersecurity researcher Jeremiah Fowler, highlighting the scale of credential theft impacting crypto users through malware-infected devices.

The exposed database, which was publicly accessible and lacked encryption or password protection, contained more than 96 gigabytes of stolen credential data, including email addresses, usernames, passwords, and direct login URLs.

Fowler’s findings indicate the credentials were harvested using infostealer malware rather than through direct breaches of the affected platforms.

The presence of Binance-linked records does not suggest a compromise of Binance’s internal systems. Instead, the data appears to have been collected from individual users whose devices were infected with credential-stealing software.

Binance Records Part Of Widespread Financial Exposure

Fowler reported that the dataset included credentials tied to a broad range of financial services, crypto wallets, and trading platforms.

Alongside the Binance-referenced records, the database contained logins associated with banks, credit cards, and other crypto platforms, highlighting how infostealer malware has become a primary vector for account takeovers.

The dataset’s structure showed signs of organized data collection.

Records were indexed using reversed host paths and unique hash identifiers, enabling easy cataloguing by victim and service.

According to Fowler, this level of organization increases the likelihood that the credentials could be used in automated credential-stuffing attacks against exchanges and financial platforms.

Also Read: How Europe Became America's Biggest Foreign Owner With $10.4 Trillion U.S. Stock Bet

Government Credentials Raise Additional Concerns

Beyond consumer and financial accounts, Fowler identified credentials associated with .gov email domains from multiple countries.

While not all government accounts provide access to sensitive systems, exposed credentials could be leveraged for impersonation, targeted phishing, or as footholds into official networks.

The inclusion of government-linked accounts elevates the incident beyond consumer cybersecurity, introducing potential national security and public safety risks depending on the affected users’ roles.

Database Left Publicly Accessible for Weeks

Fowler said the database had no identifiable owner and was hosted on cloud infrastructure without basic security controls.

After discovering the exposure, he reported it directly to the hosting provider. Despite multiple attempts, access was not restricted for nearly a month, during which the number of exposed records continued to increase.

The hosting provider declined to disclose who controlled the database, and it remains unclear how long the data was publicly accessible before Fowler discovered it or whether others accessed it during that period.

Although the exposed database has since been taken offline, Fowler warned that once such datasets surface, copies are often redistributed, making the long-term impact difficult to fully contain.

Read Next: Are We On The Cusp Of A Bear Market As Crypto Liquidity Drains And Metals Rally?

Share to:

This content is for informational purposes only and does not constitute investment advice.

Curated Series

SuperEx Popular Science Articles Column

SuperEx Popular Science Articles Column

This collection features informative articles about SuperEx, aiming to simplify complex cryptocurrency concepts for a wider audience. It covers the basics of trading, blockchain technology, and the features of the SuperEx platform. Through easy-to-understand content, it helps users navigate the world of digital assets with confidence and clarity.

Unstaked related news and market dynamics research

Unstaked related news and market dynamics research

Unstaked (UNSD) is a blockchain platform integrating AI agents for automated community engagement and social media interactions. Its native token supports governance, staking, and ecosystem features. This special feature explores Unstaked’s market updates, token dynamics, and platform development.

XRP News and Research

XRP News and Research

This series focuses on XRP, covering the latest news, market dynamics, and in-depth research. Featured analysis includes price trends, regulatory developments, and ecosystem growth, providing a clear overview of XRP's position and potential in the cryptocurrency market.

How do beginners trade options?How does option trading work?

How do beginners trade options?How does option trading work?

This special feature introduces the fundamentals of options trading for beginners, explaining how options work, their main types, and the mechanics behind trading them. It also explores key strategies, potential risks, and practical tips, helping readers build a clear foundation to approach the options market with confidence.

What are the risks of investing in cryptocurrency?

What are the risks of investing in cryptocurrency?

This special feature covers the risks of investing in cryptocurrency, explaining common challenges such as market volatility, security vulnerabilities, regulatory uncertainties, and potential scams. It also provides analysis of risk management strategies and mitigation techniques, helping readers gain a clear understanding of how to navigate the crypto market safely.