Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·TNoKQx…ogULSummary
BingX is a Singapore-headquartered centralized cryptocurrency exchange founded in 2018 (originally as Bingbon), operating across 160+ countries with over 10 million reported users. In September 2024, the exchange suffered a confirmed hot wallet breach totaling approximately $52 million across at least seven blockchain networks, with on-chain forensics subsequently linking the attack to North Korea's Lazarus Group. The exchange pledged full user compensation from reserves and resumed withdrawals within days, but independently unverified regulatory claims and initial opacity around the breach raise ongoing due-diligence concerns.
Connected Entities
1 entitiesTimeline(10 events)
2018
Exchange founded under the name Bingbon.
2021
Bingbon rebrands to BingX.
June 2023
BingX publicly announces MSB registrations in the US (FinCEN) and Canada (FINTRAC); claims not independently verified in public registrant databases.
20 September 2024
Hot wallet breach detected at approximately 4:00 AM Singapore time; BingX suspends deposits and withdrawals, initially describing the event as 'temporary wallet maintenance.' Security firms Cyvers and PeckShield flag suspicious outflows of $26–43 million across seven blockchain networks.
20 September 2024
Cyvers attributes behavioral patterns of the attacker to tactics consistent with North Korea's Lazarus Group, though formal attribution is not confirmed at this stage.
21 September 2024
BingX acknowledges the security breach publicly. CPO Vivien Lin pledges full user reimbursement from company reserves. Estimated losses revised upward to approximately $52 million.
21 September 2024
BingX begins working with SlowMist and Chainalysis on forensic investigation. $10 million in stolen assets frozen.
22 September 2024
BingX restores deposits and withdrawals for USDT, USDC, BTC, ETH, TRX, and SOL. Accusations of a cover-up dismissed by CPO Vivien Lin via public AMA.
22 February 2025
Blockchain investigator ZachXBT publishes on-chain analysis demonstrating that an address used in the BingX hack is directly connected to the address cluster behind the Phemex hack and the $1.5 billion Bybit hack, linking all three incidents to Lazarus Group.
23 February 2025
ZachXBT further links Poloniex to the same Lazarus Group cluster, identifying four major exchange hacks connected to a single threat actor.
Decision Log
- hash: 9XB9QAf6ES4L7gvrajsVo3warqrnbDnJ5HH8nyBPpxad
This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 19 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:28 AM
last updated: 8/30/2026, 5:14:06 AM
avoid.net — verified advice for a post-truth world