Open app

HostDeFi › Is BingX safe

Is BingX safe? The exchange that covered $52M and called it minor

BingX's file is the strangest shape in the breached-but-covered tier: a genuinely fast, genuinely complete cover reflex — withdrawals back inside 24 hours, a self-financed Safety Fund buying replacement tokens on the open market, zero user losses — wrapped around a disclosure choice that kept insisting a $52 million theft was 'minor'. Both halves are on the record, and the honest answer needs both.

Updated September 28, 2026 · By the HostDeFi editorial desk · Sources linked throughout; vendor claims labeled.

What BingX is

BingX is a Singapore-headquartered centralized exchange — spot, futures, and a heavy copy-trading product — that grew into a mid-tier venue large enough to matter without the major-league scrutiny of Binance or Coinbase. It sits in the same regulatory tier as the second-wave Asian exchanges: global user base, thin primary-market licensing, marketing louder than its disclosure. The safety question for a venue like this is almost never 'will they get hit' — mid-tier exchanges all get hit — it is what the balance sheet and the operating reflex do in the 48 hours after.

On September 20, 2024, that question got its real-world answer.

September 20, 2024: the two-phase drain

At roughly 4:00 AM Singapore time, BingX's security systems flagged abnormal outbound activity from a hot wallet. On-chain reconstruction — Cyvers flagged it in real time, PeckShield within hours — showed the drain fanning out across at least ten recipient addresses over multiple hours: Ethereum, Avalanche, BNB Chain, Optimism, Polygon, Base, Arbitrum. The pattern read as sustained access to a shared signing pipeline rather than a one-shot exploit, which is why the loss figure kept moving: PeckShield's first count was ~$26.7M, then ~$43M as more wallets surfaced; Beosin put it at ~$45M across three funding lines; SlowMist ~$47M; Cyvers's all-chain sum landed at ~$52M.

The honest framing of the response is two-layered. Operationally, it was good: withdrawals for USDT, USDC, BTC, ETH, TRX, XRP and SOL resumed within 24 hours, deposits within 48, 129 tokens had services restored by September 29, trading never stopped, and security firms helped freeze ~$1M of the stolen funds. Disclosure-wise, it was not: the first public statement called it 'wallet maintenance', and the Chief Product Officer kept describing the theft as a 'minor' loss while the forensics figure climbed toward $52M — roughly double what PeckShield had already attributed by the time the word was used.

The Safety Fund — what the cover actually was

The make-whole mechanism deserves the credit it earned. Rather than simply writing off the hole, BingX established a Safety Fund financed entirely from its own capital and used it to buy the stolen tokens back on the secondary market — replenishing the drained denominations so withdrawals could reopen in-kind rather than forcing users onto claims or IOUs. The process was ~90% complete by September 30, with the remainder gated on security re-testing of dozens of chains. User assets, the company stated and the withdrawals corroborated, were never impaired.

That is the best-case shape for an uninsured mid-tier incident: the venue absorbed the loss the way it promised, on a clock comparable to CoinEx's clean 2023 execution. The asterisk is investigative, not financial: BingX's CPO said investigators believed 'the same hacker group responsible for past similar incidents' was behind it — the Lazarus-attribution family that hit Indodax days earlier — but no formal root-cause report, indictment, or recovery beyond the ~$1M frozen has been published. The money was made whole; the 'how did they get in' was never answered in public.

Why 'minor' still costs trust

The disclosure posture matters because it is the one part of the incident fully inside the exchange's control — and it chose the minimizing frame at exactly the moment the on-chain record was saying otherwise. 'Wallet maintenance' for a live multi-chain drain, 'minor' for a sum that settled near $52M, and a Security-events FAQ that leads with reassurance rather than numbers. For a user deciding whether the next incident's announcements can be taken at face value, that is the operative data point: the cover was real, and so was the spin.

Compare the tier honestly: CoinEx in 2023 published the mechanism, the foundation paying, the rebuild timeline; Deribit published the wallet-server compromise in detail the same day; BingX published reassurance and let SlowMist and PeckShield supply the numbers. A venue that pays fast but narrates slow is safer than one that does neither — and measurably less trustworthy than one that does both.

The residual risks

The standing risks are the mid-tier set, sharpened by the incident's own lesson: a shared signing pipeline able to drain seven-plus chains in one window means hot-wallet blast radius is architectural, not per-chain — 'cold-majority reserves' only bounds it if the hot ceiling stays honest. Copy-trading adds a second failure class the breach file says nothing about: strategy-provider incentives and liquidation cascades are product risk, not custody risk. And the regulatory posture — Singapore-headquartered, offshore-served, no top-tier license named in its own materials — means the jurisdictional backstop that made Bitstamp's or bitFlyer's files readable is absent.

The counterweights are real too: the Safety Fund precedent now exists and was demonstrated, not promised; the freeze coordination produced an actual ~$1M recovery; and the venue stayed solvent under a $52M hit without touching user balances — a solvency data point most mid-tier exchanges have never had to produce. The second year since has added no second incident, which matters for a venue whose first hit arrived through infrastructure rather than through users.

Where BingX stands

In the breached-and-covered family BingX is the 'pay fast, narrate slow' entry — structurally similar to CoinEx's execution but with the disclosure debt CoinEx avoided. The verdict the file supports: custody-side, the reflex and the balance sheet both proved real; trust-side, a venue that calls $52M minor will call the next number whatever suits it, so the on-chain forensics — not the announcements — are the load-bearing source. A user holding funds there is relying on a reserve that proved itself once, inside an incident whose entry mechanism was never publicly explained.

Frequently asked questions

Was BingX hacked?

Yes — September 20, 2024, ~4:00 AM Singapore time. A compromised hot wallet drained funds across seven-plus chains (Ethereum, Avalanche, BNB, Optimism, Polygon, Base, Arbitrum) in a two-phase, multi-hour extraction through at least ten recipient addresses. Final estimates: ~$43–52M.

Did BingX users lose money?

No documented user loss. Withdrawals for major assets resumed within 24 hours, deposits within 48, and BingX's self-financed Safety Fund bought replacement tokens on the open market so services could reopen in-kind. All user balances stayed unimpaired.

Why did BingX call a $52M hack 'minor'?

That framing is part of the file, not beside it: the first public statement called the drain 'wallet maintenance' and the CPO kept using 'minor' while forensics firms climbed from ~$26.7M to ~$52M. Operationally the cover was excellent; the minimizing language is the reason the incident still costs trust.

Who attacked BingX?

BingX's CPO said investigators believed it was the same group behind 'past similar incidents' — consistent with the Lazarus-linked pattern attributed around that period's Asian-exchange hits (Indodax days earlier). No formal attribution, indictment, or root-cause report has been published.

Was any of the stolen money recovered?

About $1M was frozen with the help of security firms early in the response. The rest moved through the multi-address fan-out typical of the actor class; the Safety Fund — not recovery — is what made users whole.

How does BingX compare to CoinEx?

Same reflex, different disclosure. Both suspended fast, rebuilt, covered from reserves, and lost nothing on the user side. CoinEx published mechanism and timeline precisely; BingX published reassurance while third-party trackers supplied the numbers — the difference between an incident report and an incident narrative.

HostDeFi is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a HostDeFi product