Binance announced on March 11, 2018 that it would pay a $250,000 U.S.-dollar-equivalent bounty in BNB for information leading to the legal arrest of the people behind an attempted attack on its exchange four days earlier. The company also said it had allocated the equivalent of $10 million in cryptocurrency reserves for future rewards connected to illegal hacking attempts against Binance.
The terms made the offer more specific than a general appeal for tips. Binance said the first person to provide substantial information and evidence producing a legal arrest in any jurisdiction would qualify. The BNB conversion rate would be set when the reward was transferred, so the promise fixed a dollar-equivalent value rather than a token quantity. Binance also reserved discretion to divide the bounty when information from multiple sources contributed to arrests.
The announcement did not report an arrest, identify a suspect or say that any reward had been paid. It was a private-company incentive, not a government reward or a finding by a court.
From account phishing to attempted market manipulation
The bounty followed abnormal trading on March 7, 2018. Binance described that episode as an unsuccessful, large-scale and organized attempt. A contemporaneous BleepingComputer report, drawing on Binance's incident account, said attackers had collected user credentials through a phishing campaign and created trading API keys for compromised accounts.
That report placed the concentrated trading activity at approximately 14:58–14:59 UTC on March 7. It said compromised accounts sold bitcoin and bought Viacoin, while 31 accounts prepared by the attackers stood ready to sell VIA. Binance's internal controls detected the abnormal activity and stopped withdrawals, according to the report. The account therefore described an attempted theft and manipulation scheme routed through customer credentials, not a demonstrated compromise of Binance's core systems.
Those technical details were substantially dependent on Binance's own investigation. No complete independent forensic report, law-enforcement filing or court record was available in the reviewed contemporaneous record on March 11. Cointelegraph's same-day report accordingly treated the exact method as not yet fully established publicly, while noting the focus on API keys.
Why the bounty mattered
The program widened the exchange's response from technical containment to identification and arrest. That mattered because centralized crypto venues combined custody, account access, order execution and withdrawal controls. Stolen credentials could be used to distort trading even if an exchange's underlying platform had not been breached. The March 7 sequence illustrated that market-integrity risk and account-security risk were connected.
The payment design also tied enforcement incentives to Binance's own asset. A $250,000 equivalent award paid in BNB could change in token quantity depending on the exchange rate at transfer. The announcement did not specify the valuation venue, timing process, escrow arrangement or composition of the separate $10 million crypto reserve. Those omissions limited how independently outsiders could evaluate the commitment.
Binance invited other exchanges and cryptocurrency businesses to join the initiative. That was an attempt to frame security as a collective industry problem rather than an incident isolated to one venue. Yet the March 11 announcement supplied no shared governance, information-sharing standard or formal law-enforcement partnership.
The event-day record
What was verifiable on March 11 was the offer: its $250,000 dollar-equivalent ceiling, payment in BNB, arrest condition, possible division among sources and the company's stated $10 million reserve for future bounties. Binance's claim that the March 7 attempt failed was corroborated by contemporaneous reporting, but it remained a company assertion supported by its internal controls and incident narrative.
The significance was therefore institutional rather than a measured market-price reaction. Binance was using its balance sheet and exchange token to create an investigative incentive after a phishing-driven trading incident. The record did not yet establish who carried out the attempt, whether an arrest would follow or whether the bounty would ever be paid.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

