Binance said on December 11, 2022 that it was investigating abnormal price movements involving SUN, ARDR, OSMO, FUN and GLM, then temporarily restricted withdrawals from some accounts that had profited from the activity. Chief executive Changpeng Zhao later said the exchange’s investigation had found no linkage among the accounts it reviewed and characterized the episode as market behavior rather than an account compromise.
The incident mattered beyond the five named tokens. It showed, weeks after FTX’s collapse, how a centralized crypto venue could intervene in customer access while deciding whether unusual trading reflected manipulation, stolen credentials or ordinary speculation. Binance’s statements established that it took action; they did not disclose how many accounts were affected, how long every restriction lasted, or what dollar value was held.
An investigation changed course
Binance’s official account first said it had observed abnormal movements in trading pairs involving the five assets and was taking action regarding suspicious accounts. It added that the activity did not appear to result from compromised accounts or stolen application-programming-interface keys and said customer funds were safe.
Zhao then described the exchange’s preliminary reconstruction. According to him, one participant deposited funds and began buying, other traders followed, and investigators could not see connections among the accounts. That was an exchange finding, not an independently audited forensic conclusion.
The operational response was more concrete. Zhao acknowledged that Binance had temporarily locked withdrawals on some accounts that profited from the trades. He said the exchange reversed restrictions after complaints arrived through social media in multiple countries. Binance did not say that trading across the platform had stopped, and the surviving statements do not support describing the episode as a platform-wide withdrawal freeze.
That distinction is important. A targeted account restriction can prevent a customer from moving assets while leaving the exchange and its other withdrawal channels operating. It can also serve as a risk-control tool while staff examine coordinated trading. But without disclosed thresholds, account counts or an incident report, outsiders could not test whether Binance applied those controls consistently or proportionately.
The market claim had limits
Zhao also acknowledged the criticism that the exchange had intervened too aggressively. He said there was a balance between platform action and allowing a free market to play out. The sequence exposed a basic tension in centralized crypto trading: the venue maintains the order book and custody ledger, monitors behavior, and can suspend access, even when the assets traded originate on open blockchain networks.
No reliable consolidated price claim can be made from Binance’s December 11 statements. The exchange named assets, not every affected trading pair, measurement window, opening price, peak, low, volume or order-book depth. Crypto markets also trade continuously across venues. Reports describing spectacular token moves therefore require pair-level trade data and a defined UTC interval before they can be treated as verified market measurements. This reconstruction does not supply an unverified percentage.
The event-day evidence was also provisional about causation. Binance said the specific activity it reviewed did not appear to involve stolen accounts or API keys. That wording did not prove that every unusual trade on December 11 was benign, nor did it resolve separate reports of unauthorized API trading that had circulated before the episode.
Why December 11 mattered
The intervention came in a market newly focused on exchange custody and controls after FTX entered bankruptcy on November 11, 2022. Against that backdrop, even temporary restrictions invited scrutiny. The consequential fact was not that Binance had failed or been hacked; neither was established. It was that a leading trading venue could first treat profitable accounts as suspicious, restrict withdrawals, and then reverse course after concluding the visible pattern lacked coordinated-account links.
Later context
On December 29, 2022, 3Commas confirmed that some users’ API credentials had been disclosed after data appeared on December 28. That later admission corrected 3Commas’ earlier assumptions about its own systems, but it does not establish that the five-token Binance episode on December 11 was caused by those credentials. The two records should not be collapsed into one incident without account-level forensic evidence.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

