Informations
Jump to content

Lorem Ipsum...

Click to Dismiss this Notification
Ładowanie danych...
  • 149 Million Stolen Logins Exposed: What Crypto Users Should Do Next

    Please Register !

    What was discovered?

    A huge, publicly accessible database containing stolen usernames and passwords was recently spotted by cybersecurity researcher Jeremiah Fowler. The credentials appear to have been collected from infected personal devices (phones and computers) using infostealer malware—a type of malicious software that quietly grabs saved logins from browsers, apps, and sometimes password managers.

    According to a blog post published on ExpressVPN, the dataset reportedly held around 149 million credential pairs. Among them were logins tied to major platforms like Facebook, Instagram, Netflix, and also the crypto exchange Binance—including about 420,000 credentials associated with Binance users.


    Please Register !

    What’s inside the leak (high-level numbers)

    The dump reportedly included, among others:

    • Please Register !

      48M Gmail accounts

    • Please Register !

      4M Yahoo accounts

    • Please Register !

      17M Facebook accounts

    • Please Register !

      6.5M Instagram accounts

    • Please Register !

      3.4M Netflix accounts

    • Please Register !

      780K TikTok accounts

    • Please Register !

      420K Binance-related credentials (at least)

    Fowler also noted that in the portion he reviewed, there were signs of compromised access affecting financial services, including trading accounts, banking, and potentially crypto wallet-related logins.

    Please Register !


    Please Register !

    Why government-related logins are especially worrying

    One of the more alarming parts of Fowler’s comments was the mention of credentials connected to government-linked accounts and .gov domains. That’s risky because it can fuel:

    • Please Register !

      impersonation attempts (attackers pretending to be a government agency)

    • Please Register !

      phishing campaigns aimed at citizens or employees

    • Please Register !

      targeted attacks using “official-looking” emails


    Please Register !

    Important clarification: this is NOT proof Binance’s systems were hacked

    Security experts emphasized that this does not automatically mean Binance suffered an internal breach. The more likely scenario is:

    Please Register !

    Infostealer malware infected users’ devices

    Please Register !

    stole saved credentials →

    Please Register !

    those logins ended up in a database dump.

    A Binance spokesperson reportedly explained that these are credentials stolen from compromised devices, not “leaked from Binance.”

    Deddy Lavid (CEO of blockchain cybersecurity firm Cyvers) also stressed the same point: it looks like an end-user device compromise, not an exchange back-end failure.


    Please Register !

    What Binance reportedly does in these cases

    The article notes that Binance works to reduce harm by:

    • Please Register !

      monitoring dark-web marketplaces

    • Please Register !

      warning affected users

    • Please Register !

      forcing password resets when needed

    • Please Register !

      revoking suspicious or compromised sessions

    Binance also recommends using antivirus / anti-malware tools and running regular scans to catch threats like infostealers early.


    Please Register !

    Infostealers targeting crypto via “game mods” (Kaspersky warning)

    The piece also references a warning from Kaspersky (December 2025) about a newer infostealer campaign that pretends to be game cheats or mods. It reportedly aims at:

    • Please Register !

      crypto wallets

    • Please Register !

      browser extensions (especially wallet extensions)

    • Please Register !

      account sessions and saved passwords

    It was reportedly found in November, and attackers were said to hide it inside game cracks/mods, with frequent references to Roblox-themed bait.


    Please Register !

    What you should do right now (practical checklist)

    If you trade crypto or use wallet extensions, this is the “do it today” list:

    Please Register !

    1) Change passwords (start with email!)

    • Change your email password first (because password resets go there).

    • Then change exchange and social passwords.

    • Use a unique password for each site (password manager helps a lot).

    Please Register !

    2) Turn on stronger 2FA

    • Please Register !

      Prefer Authenticator app or hardware security key

    • Please Register !

      Avoid relying only on SMS 2FA if you can

    Please Register !

    3) Clean your device

    • Run a full malware scan

    • Remove unknown browser extensions

    • Update your OS and browser

    Windows (built-in Defender quick examples)

    # Update Defender signatures Update-MpSignature # Quick scan Start-MpScan -ScanType QuickScan # Full scan (takes longer) Start-MpScan -ScanType FullScan

    Please Register !

    4) If you use wallet extensions

    • Remove suspicious extensions immediately

    • Consider moving funds to a fresh wallet if you suspect compromise

    • Treat any exposed seed phrase as burned (create a new wallet)

    Please Register !

    5) Watch for phishing after leaks

    After big dumps, attackers often launch follow-up scams:

    • “Security alert: log in now”

    • “Your account is at risk”

    • “Verify your wallet”

    If a message pressures you with urgency, slow down—that’s the point.

     Share



    User Feedback

    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.

    Guest

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.

spacer.png

Disable AdBlock
The popup will be closed in 5 seconds...