A High-Profile Breach Exposes the Fragility of Web2 Security in the Crypto Elite
A hacked WeChat account targeting Binance’s Yi He exposes ongoing weaknesses in Web2 security across the crypto industry.
The breach of Binance co-CEO Yi He’s WeChat account has become an unexpected stress test for the security limits of traditional social platforms, shaking a corner of the crypto world that has grown accustomed to digital threats but not necessarily from legacy Web2 channels. Yi, who recently assumed her new leadership role at Binance, revealed on X that her WeChat account had been hijacked and weaponized to promote a little-known BNB Chain memecoin in what rapidly unfolded as a classic pump-and-dump scheme. According to her, she no longer actively uses the platform, and attackers gained control by compromising the phone number once associated with the account, leaving her temporarily locked out.
The incident quickly gained visibility after Binance founder Changpeng Zhao urged the public to ignore the fraudulent posts, warning that Web2 social tools remain structurally vulnerable. His caution echoed a persistent concern within the industry: the gap between high-stakes digital finance and the comparatively low-security frameworks of mainstream communication apps. The breach illustrates how threat actors continue to exploit that imbalance.
Blockchain analytics firm Lookonchain reported that the attackers created two fresh wallets ahead of the scheme, purchasing over 21 million tokens of a memecoin named Mubarakah using roughly $19,000 in USDT. Once they commandeered Yi’s account, they posted promotional messages to her followers, triggering an 800% spike in the token’s value. The price quickly cratered as the attackers began unloading their holdings. According to Lookonchain’s data, they converted almost 12 million tokens for more than $43,000 in USDT, swapping those gains for ether. They still control another tranche valued at approximately $31,000, placing their provisional profits at around $55,000 while awaiting further liquidation.
Yi later confirmed that her access had been restored through external verification measures. She cautioned that some individuals were attempting to impersonate legitimate support requests to re-establish contact, urging users not to trust any unexpected friend requests or private messages. Her warning reflects a broader truth: scams increasingly rely on social engineering rather than purely technical intrusions.
This exploit arrives at a delicate moment for Binance. Yi’s appointment as co-CEO, shared with Richard Teng, was announced just days earlier during the company’s Blockchain Week in Dubai, marking a significant leadership transition for the world’s largest crypto exchange by volume. While Binance has faced regulatory headwinds and heightened scrutiny in the U.S. and abroad, the company continues to emphasize operational resilience and platform security. But as this incident shows, even the most influential industry figures can be undermined through relatively simple entry points.
The breach also follows another security lapse from October, when the official X account of the BNB Chain network, boasting nearly four million followers, was compromised and used to circulate phishing links. The episode resulted in about $8,000 in user losses before the affected accounts were compensated. Taken together, the events highlight an uncomfortable reminder: the weakest link in crypto security may still reside in the platforms that were never designed for safeguarding financial ecosystems.



