Binance said on August 7, 2019 that it was investigating an extortion attempt involving thousands of images that allegedly resembled records collected during customer identity verification. According to the exchange, an unidentified person demanded 300 bitcoin in return for withholding 10,000 photographs and began distributing material after Binance refused to cooperate.

The disclosure mattered beyond one exchange. Cryptocurrency trading platforms were increasingly collecting passports, identity cards and facial photographs to satisfy know-your-customer requirements. The incident therefore exposed a difficult institutional tradeoff: identity checks intended to control financial crime could also create concentrated stores of sensitive personal information.

What Binance verified

Binance verified the demand, the threatened publication of purported customer records and its own investigation. It also offered a reward of up to 25 BTC for information that could identify the person and support legal action. Bloomberg reported the offer and investigation on August 7, attributing the central figures to Binance’s statement.

Those numbers describe claims and offers, not completed transactions. There was no evidence on August 7 that Binance paid the requested 300 BTC or that the full set of 10,000 images existed. Coinburn has not converted either bitcoin amount into dollars because a conversion would depend on the selected exchange, currency pair and intraday timestamp. Contemporary dollar estimates from other publications consequently varied.

Binance said it had notified relevant authorities and was pursuing possible sources of the images. Its statement did not identify a jurisdiction, investigating agency or suspected individual, leaving the status of any law-enforcement inquiry unclear.

What remained unproved

The central uncertainty was provenance. Binance said the publicly circulated images contained inconsistencies when compared with its systems and lacked the hidden digital watermark applied through its verification process. On that basis, the exchange said no evidence then established that the images had been obtained directly from Binance.

The exchange also said its initial review placed the visible material in February 2018, when a third-party vendor was helping process a high volume of verification requests. Binance said it was investigating with that vendor. That observation created a plausible external route for exposure, but it did not establish that the vendor was responsible or that every circulated image was authentic.

Contemporaneous CoinDesk reporting complicated a simple dismissal. The publication reported receiving hundreds of files from the person behind the claims and said it confirmed that at least two profiles corresponded to people who had supplied identifying information when opening Binance accounts. CoinDesk also reported that one examined image appeared altered. Those checks supported the possibility that some material related to real customers, but they did not prove the claimed scale, the route of acquisition or a breach of Binance’s own systems.

Why the episode mattered

KYC records carry a different risk from stolen cryptocurrency. A compromised password can be changed, while a passport image, legal name or face cannot be replaced as easily. Such records can facilitate impersonation or targeted phishing even when exchange balances and private keys remain untouched. Binance did not report missing customer funds in connection with the August 7 disclosure.

The episode also demonstrated why the words “leak,” “hack” and “breach” could not be treated as interchangeable. Images were circulating, an extortion demand was documented and some records appeared connected to actual customers. But the available evidence did not establish that attackers penetrated Binance on or before August 7, nor did it establish that 10,000 Binance records had been taken.

Contemporaneous assessment

The defensible conclusion on August 7, 2019 was narrower than either a confirmed breach or a complete hoax: Binance faced a documented extortion campaign built around disputed identity-verification material. Its investigation and 25 BTC reward were verified corporate actions. The authenticity, scope and custody path of the images remained unresolved, making categorical claims about a Binance systems breach premature.

Primary sourceBinance — Statement on False “KYC Leak”

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.