{"id":31955,"date":"2020-11-18T14:09:12","date_gmt":"2020-11-18T12:09:12","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=31955"},"modified":"2025-08-28T06:18:04","modified_gmt":"2025-08-28T03:18:04","slug":"some-of-the-bitcoin-stolen-from-ledger-users-ends-up-on-binance","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/some-of-the-bitcoin-stolen-from-ledger-users-ends-up-on-binance\/","title":{"rendered":"Some of the Bitcoin stolen from Ledger users ends up on Binance"},"content":{"rendered":"<p>The organizers of the phishing attack against Ledger hardware-wallet users moved 51 BTC to the Binance exchange. The Telegram channel <a href=\\\"https:\/\/t.me\/gfoundinshit\/4986\\\" target=\\\"_blank\\\" rel=\\\"noopener noreferrer\\\">reported<\/a> this, via Goldfoundinshit TM.<!--more--><\/p>\n<p>Funds from one of the hacker wallets <a href=\\\"https:\/\/www.blockchain.com\/ru\/btc\/address\/bc1qrzpl4y8qvpngkfqdh9apjs8maajp4fvkzk3exa\\\" target=\\\"_blank\\\" rel=\\\"noopener noreferrer\\\">arrived<\/a> at the trading platform directly, without using mixers.<\/p>\n<p>According to Goldfoundinshit TM, the attackers registered several accounts on Binance and sent no more than 2 BTC to each of them, in order not to exceed the verification threshold.<\/p>\n<blockquote>\n<p>&#8220;The phishers used several iterations from the main wallet. They sent a small amount directly to the deposit address, and the main amount later,&#8221; wrote the Telegram channel.<\/p>\n<\/blockquote>\n<p>According to the Crypto AML Telegram bot, the original hacker wallet poses a 100% risk and contains stolen coins. The risk for the other attacker addresses is also above 50%.<\/p>\n<div id=\\\"attachment_116959\\\" style=\\\"width: 524px\\\" class=\\\"wp-caption alignnone\\\"><img loading=\\\"lazy\\\" decoding=\\\"async\\\" aria-describedby=\\\"caption-attachment-116959\\\" class=\\\"wp-image-116959 size-full\\\" src=\\\"https:\/\/u1f987.com\/wp-content\/uploads\/2020-11-18-13.07.32.jpg\\\" alt=\\\"Part of the Bitcoin stolen from Ledger users ended up on Binance\\\" width=\\\"514\\\" height=\\\"347\\\" srcset=\\\"https:\/\/u1f987.com\/wp-content\/uploads\/2020-11-18-13.07.32.jpg 514w, https:\/\/u1f987.com\/wp-content\/uploads\/2020-11-18-13.07.32-300x203.jpg 300w\\\" sizes=\\\"auto, (max-width: 514px) 100vw, 514px\\\" \/><\/p>\n<p id=\\\"caption-attachment-116959\\\" class=\\\"wp-caption-text\\\">Source: Telegram channel Goldfoundinshit TM.<\/p>\n<\/div>\n<p><strong>Update:<\/strong> Binance representatives told ForkLog that for AML and blockchain analytics the exchange uses professional products, not random Telegram bots.<\/p>\n<blockquote>\n<p class=\\\"p1\\\">&#8220;Bots, such as Whale Alert and similar services, often mislabel addresses as belonging to Binance,&#8221; they noted.<\/p>\n<\/blockquote>\n<p>Back in October, Ledger <a href=\"https:\/\/u1f987.com\/en\/news\/ledger-users-report-mass-phishing-attack\">began<\/a> receiving phishing emails that urged users to install an emergency update. Through this, hackers gained access to the cryptocurrency.<\/p>\n<p>The victims <a href=\"https:\/\/u1f987.com\/en\/news\/ledger-reports-data-breach-affecting-around-one-million-users\">linked<\/a> the attack to the July data breach of about a million users from a marketing database. However the wallet developers said they have not yet been able to confirm this hypothesis.<\/p>\n<p>In early November, the stolen funds moved. The hackers <a href=\"https:\/\/u1f987.com\/en\/news\/organisers-of-phishing-attack-on-ledger-users-move-107-btc\">sent<\/a> 107 BTC to two Bitcoin wallets and <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-moved-1-15-million-xrp-stolen-from-ledger-users\">transferred<\/a> 1.15 million XRP in five payments to the Bittrex exchange address.<\/p>\n<p>Subscribe to ForkLog news on Telegram: <a href=\\\"https:\/\/t.me\/forklogfeed\\\" target=\\\"_blank\\\" rel=\\\"nofollow noopener noreferrer\\\">ForkLog Feed<\/a> \u2014 the full feed of news, <a href=\\\"https:\/\/telegram.me\/forklog\\\" target=\\\"_blank\\\" rel=\\\"nofollow noopener noreferrer\\\">ForkLog<\/a> \u2014 the most important news and polls.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Organisers of the phishing attack on Ledger hardware-wallet users moved 51 BTC to Binance. The Telegram channel Goldfoundinshit TM reported this.<\/p>\n","protected":false},"author":1,"featured_media":31956,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[744,1154,1640],"class_list":["post-31955","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-binance","tag-crimes","tag-ledger"],"aioseo_notices":[],"amp_enabled":true,"views":"20","promo_type":"1","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/31955","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=31955"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/31955\/revisions"}],"predecessor-version":[{"id":31957,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/31955\/revisions\/31957"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/31956"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=31955"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=31955"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=31955"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}