Binance users encountered significant asset losses as a result of a malicious Chrome extension, causing concern over the platform's response time and actions following the incident.
A Twitter user named @CryptoNakamao revealed the loss of nearly $1 million from his Binance account without hackers obtaining his password or 2FA codes. The attackers manipulated his account using hijacked webpage cookies, engaging in arbitrage trading to empty his account.
Chrome Extension "Aggr" Blamed for Binance Hack: Allegations of Delayed Response and Fund Losses
The user attributed the attack to his use of the Chrome extension "Aggr," recommended by overseas influencers and certain Telegram channels. Hackers exploited this extension to collect user cookies, enabling them to control accounts without passwords or 2FA codes, facilitating theft through arbitrage trading.
Despite knowledge of the malicious extension weeks prior, Binance allegedly failed to promptly alert users, allowing its promotion and exacerbating fund losses. Additionally, Binance's response time to freeze the hacker's funds was criticized as slow, resulting in irreversible losses for affected users.
Binance defended its actions, stating that the incident resulted from users' compromised personal devices due to the installation of the malicious extension. The platform emphasized its rapid response to freeze requests and highlighted the time-consuming process of investigating arbitrage trading across platforms.
The community debates whether Binance should compensate affected users. Some argue that Binance's delayed response contributed to the losses, while others maintain that users' actions led to the security breach. Regardless, users are reminded to exercise caution when installing browser extensions and to remain skeptical of unsolicited messages.
The incident underscores the risks associated with browser extensions and the importance of platform vigilance in addressing security threats promptly. Users are urged to prioritize security measures to safeguard their assets in the evolving landscape of digital finance.