Binance completed a system upgrade and restarted trading at 13:00 UTC on May 15, 2019, restoring a major part of its exchange after a security breach removed 7,000 BTC from one of its hot wallets on May 7.

Deposits and order management were available before trading resumed. Withdrawals were restored progressively rather than at one clearly documented, platform-wide moment. That distinction is important: Binance had reopened its marketplace, but customers’ ability to move every supported asset off the exchange was not proven to have returned simultaneously.

The restart mattered because the incident had tested more than Binance’s ability to absorb a theft. It exposed how customers of a centralized cryptocurrency exchange depended on the operator’s internal authentication, withdrawal screening and custody systems even while the underlying Bitcoin network continued processing transactions normally.

Eight days from breach to restart

Binance said it detected the breach at 17:15:24 UTC on May 7. According to the exchange’s account, attackers obtained user API keys, two-factor-authentication codes and potentially other information through techniques that included phishing and malicious software. They then withdrew 7,000 BTC in a single transaction that passed Binance’s existing security checks.

The referenced Bitcoin transaction is independently visible in the public ledger. The transaction record verifies the movement of bitcoin, but it does not by itself establish who controlled the sending wallet, identify the attackers or prove how they obtained access. Attribution to Binance and the description of the intrusion therefore remain based on the exchange’s contemporaneous disclosure.

Binance immediately stopped withdrawals and then suspended deposits while conducting a security review. Trading initially continued inside the platform. For the final upgrade on May 15, Binance suspended trading, deposits and withdrawals beginning at 03:00 UTC. The company originally estimated six to eight hours of work, then announced a two-hour extension.

Its completion notice scheduled trading to resume at 13:00 UTC. Chief executive Changpeng Zhao separately said customers could cancel orders and that trading, new orders and deposits would resume first, with withdrawals following shortly afterward. Contemporaneous reports differed on whether withdrawals were already generally available during the opening minutes, reinforcing the narrower conclusion that withdrawal access returned progressively.

Security changes were company claims

Binance said it had made significant changes to its API, two-factor-authentication and withdrawal-validation systems. It also described work on risk management, user-behavior analysis, know-your-customer procedures and anti-phishing controls, while indicating that hardware authentication support was planned.

Those statements documented the company’s response, not an independent certification that the vulnerabilities had been eliminated. No public third-party audit reviewed for this reconstruction establishes the design, deployment or effectiveness of every control by May 15.

Binance also said its Secure Asset Fund for Users would cover the loss and that customer balances would not be reduced. That was a consequential commitment, but the surviving event-day sources do not provide audited fund accounts, reimbursement records or a complete accounting of affected customers. The distinction between a company assurance and independently verified compensation should therefore remain explicit.

What the reopening established

The May 15 restoration showed that Binance could resume its core market after an eight-day interruption to deposits and withdrawals. It did not reverse the Bitcoin transaction, identify the attackers or demonstrate that every compromised credential had been found.

The episode also separated protocol security from intermediary security. Bitcoin’s ledger recorded the withdrawal exactly as authorized by the credentials presented to the network-facing wallet. The failure described by Binance occurred in the exchange’s custody and account-control layers—the systems that decided whether the transaction should be authorized at all.

No price or return claim is necessary to establish the event’s significance. Restoring a large exchange removed an immediate operational constraint for its customers, but the available record does not prove that the reopening caused any particular movement in bitcoin or Binance’s exchange token on May 15, 2019.

Primary sourceBinance — System Upgrade Complete: VIP User Promotion and 50,000 BNB Community Giveaway

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.