BingX hack — September 2024
Incident facts
| Date of incident | |
|---|---|
| Target type | Centralised exchange |
| Loss | $43,000,000Published estimates range $43,000,000 to $52,000,000Price at time of incident |
| Method | Private key compromiseunauthorised intrusion into a hot wallet; BingX has never disclosed how signing keys or systems were reached |
| Chains | Ethereum, BNB Chain, Polygon |
| Outcome | Users reimbursed |
What happened
BingX, a Singapore-headquartered centralised exchange, detected an unauthorised intrusion targeting one of its hot wallets at approximately 04:00 UTC+8 on 20 September 2024. It suspended withdrawals under a wallet maintenance notice, moved remaining assets, and later published a support FAQ describing the intrusion. BingX never published a loss figure of its own. Chief product officer Vivien Lin initially called the loss minor and said a final number would be confirmed once recovery work was complete.
External estimates diverge sharply, so this record carries a range. PeckShield traced the outflows on-chain and put the total near $43 million, taken in more than one tranche; CoinDesk's account describes an initial set of transfers including about $13.25 million in ETH, $2.3 million in BNB and $4.4 million in USDT, followed by a further roughly $16.5 million. Beosin put the figure at about $45 million across three funding lines and SlowMist at about $45 million. Cyvers said its threat intelligence system summed losses across all chains at $52 million. BingX said it had frozen about $10 million, though the same Cointelegraph report cites security firms freezing around $1 million.
The attacker swapped most of the stolen tokens into ETH and BNB at decentralised exchanges including Uniswap and KyberSwap. No actor has been named and no attribution to any group or state has been made in the sources here.
BingX rejected accusations that the maintenance notice was an attempt to conceal the breach, with Lin arguing that its prompt announcement demonstrated responsibility. Its own FAQ says withdrawals for USDT, USDC, BTC, ETH, TRX, XRP and SOL resumed before 08:30 UTC+8 on 21 September and deposits for most of those assets on 22 September, with other tokens restored progressively over the following weeks. BingX said it maintains reserves sufficient to cover losses from the incident and that user assets remained unimpaired. The root cause of the hot wallet compromise has never been disclosed.
Sources
- BingXPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
- DL NewsSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "BingX hack — September 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bingxhttps://itokenly.com/hacks/bingxPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.