Binance disclosed on May 7, 2019 that attackers had withdrawn 7,000 bitcoin from the exchange’s BTC hot wallet after obtaining user API keys, two-factor authentication codes and possibly other account information. The company attributed the compromise to a combination of techniques that included phishing and viruses, while warning that it had not yet identified every potentially affected account.

The disclosure mattered beyond the size of the loss. Binance was a major global trading venue, and the incident showed how a centralized exchange could become a single operational point of failure even when the Bitcoin network itself continued processing transactions normally. Binance suspended deposits and withdrawals while beginning a security review, but said trading would continue.

What Binance established

The company said the breach was discovered on May 7 at 17:15:24 UTC. It linked the loss to one Bitcoin transaction and described 7,000 BTC as the amount withdrawn by the attackers. Binance said the transaction affected only its internet-connected BTC hot wallet, which held about 2% of its total bitcoin holdings; it represented its other wallets as secure and unharmed.

Those details were Binance’s contemporaneous account, not an independent forensic conclusion. The referenced transaction is visible in Bitcoin’s public ledger, but a blockchain record by itself does not establish who controlled every input or output, which credentials were compromised, or whether all value moved in the transaction belonged to the attacker. The attribution of 7,000 BTC to theft therefore rests principally on the exchange’s notice, corroborated by contemporaneous reporting.

Binance also said its withdrawal system raised alarms after the transaction had been executed. The exchange froze withdrawals and deposits and estimated that the security review would take about one week. It cautioned that attackers might still control some user accounts and that trading activity during the restriction required close monitoring.

The SAFU promise

Binance said it would use its Secure Asset Fund for Users, known as SAFU, to cover the incident in full and that user funds would not be affected. The fund had been introduced in July 2018, with Binance saying it would allocate 10% of trading fees to an emergency reserve held in a separate cold wallet.

On May 7, that was a company commitment rather than proof that every affected balance had already been reconciled. No public audit cited in the event-day record established the fund’s exact value, asset composition or claims process at the moment of the breach. Still, invoking SAFU was institutionally significant: Binance was attempting to separate a loss at the exchange from losses borne by customers, using a reserve created for extreme cases.

Custody and market context

The episode distinguished protocol security from intermediary security. Bitcoin’s ledger did what it was designed to do: it accepted a validly signed transaction. The failure described by Binance occurred around account access, credentials, surveillance and hot-wallet controls. Customers who used the exchange were exposed to those systems even though they did not operate the wallet themselves.

Contemporaneous reports valued the 7,000 BTC near $40 million, but that dollar figure was a point-in-time estimate that varied with bitcoin’s continuously traded price and the publisher’s observation time. This reconstruction therefore treats 7,000 BTC—not a fixed dollar conversion—as the verified loss quantity.

The immediate market response was also difficult to isolate. Prices moved after the announcement, but crypto trades continuously across venues and no reviewed source established that the breach alone caused a particular return. The firmer consequence was operational: a large exchange restricted movement of customer assets while keeping its internal market open.

What remained unknown on May 7

Binance had not published a full root-cause analysis, identified the attackers, enumerated every affected account or completed its security review by the end of May 7. It had also not demonstrated publicly that deposits and withdrawals could resume safely. Those uncertainties were part of the event itself. The verified record was a 7,000-BTC hot-wallet theft, an exchange-wide movement freeze and a promise of reimbursement—not a completed recovery.

Primary sourceBinance — Security Breach Update

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.