On 7 May 2019 Binance disclosed a “large scale security breach”. CEO Changpeng Zhao said attackers had obtained API keys, two-factor codes and other user information through phishing, malware and related tricks, waited, and then withdrew about 7,000 bitcoin — roughly $40–41 million — from a hot wallet in a single transaction that passed the shop’s existing checks. The hot wallet was said to be about 2% of Binance’s bitcoin. Cold wallets were not emptied. Withdrawals froze. Trading was to resume. The Secure Asset Fund for Users (SAFU), funded from trading fees and kept separately, would cover customers, the firm said.
KuCoin 2020 and later exchange thefts are cousins: hot keys, a company wallet. Do not collapse them. The 2023 Binance guilty plea is a different docket.
What happened
Hot wallets exist so withdrawals are fast. If someone can authorise a withdrawal the exchange will sign, the chain does what keys are for. Customers who thought they had bitcoin at Binance had a claim on Binance. SAFU is how this company chose to socialise that claim. It is not a protocol feature.
Why it matters
An insurance fund can make users whole and still leave you as a creditor of a venue. See how crypto wallets actually work, and the practical checklist, especially the part about life-changing balances on a login. API keys are keys.
What happens next
A week of closed withdrawals, other venues asked to block the destination, and a security review. We will not rank remaining exchanges. Nothing here is an instruction to use or leave Binance, or to buy, sell, or withdraw tonight.





