
BNB Chain’s official X (formerly Twitter) account, which has close to four million followers, was hijacked on Wednesday. The attackers reportedly shared phishing links designed to trick users into connecting their cryptocurrency wallets.
Binance founder Changpeng “CZ” Zhao confirmed the compromise and urged users to avoid clicking on any suspicious links. “The hacker shared multiple Wallet Connect phishing websites. Do NOT connect your wallet,” he cautioned. According to Zhao, BNB Chain’s security team has contacted X to regain access to the account and submitted takedown requests for the fraudulent domains.
Phishing Tactics Used
SlowMist’s chief security officer, known online as 23pds, explained that the attackers relied on a common deception method — altering letters in a web address to make it look genuine. He also suggested that the domains were linked to the Inferno Drainer group, a known phishing-as-a-service operation that has been active since 2022.
Inferno Drainer gained notoriety in 2023 for providing ready-made phishing kits that mimic crypto project sites, enabling affiliates to steal funds directly from unsuspecting users.
“The BNB Chain team’s security awareness shouldn’t have been this weak,” 23pds commented, highlighting the importance of stronger safeguards for official accounts.
CZ’s Advice to the Community
CZ reminded crypto holders to always double-check URLs, even if they appear on official accounts. “Always verify domains carefully, even when the post comes from a verified handle. Stay SAFU!” he posted.
At the time of reporting, the phishing posts had been removed, but it remains unclear whether any users connected their wallets or lost assets during the incident.
Key Takeaway
This hack underscores the persistent risks of social media account takeovers in the crypto industry. Users are urged to remain vigilant, verify all links, and never connect their wallets to untrusted sites.
Get the weekly commit
New blockchain deep dives every week.

