
A leaked dataset of 149 million stolen credentials has surfaced this week, reportedly including login details for around 420,000 Binance accounts. The discovery underscores a growing trend of crypto theft through long-term malware infections that steal user data directly from devices, often before any funds are moved.
The Scope of the Threat
Security firm Web3 Antivirus reported on February 4 that the dataset was compiled from information-stealing malware installed on victims’ devices. The stolen data includes exchange logins, passwords, private keys, API keys, and browser session tokens for email, social media, and financial accounts. These “infostealers” can later be used for account takeovers and fund theft, highlighting the need for early device-level detection.
Web3 Antivirus also warned that malicious AI skills on platforms like ClawHub are being used to install malware disguised as wallet tools or trading bots. These tools can remain dormant until a user’s crypto balance grows or specific actions are taken, creating upstream supply-chain risks from wallets to trusted tools.
Challenges for Users and Platforms
Crypto theft continues to cause massive losses. PeckShield reported that scams and hacks drained over $4.04 billion in 2025, with scams alone increasing 64% year over year. Centralized exchanges and large organizations were targeted most, accounting for 75% of stolen funds.
Web3 Antivirus estimated total illicit crypto activity in 2025 at $158 billion, up from $64 billion in 2024. The firm noted that even low-success attacks can cause massive losses at scale, and that the real opportunity to prevent theft lies with platforms, which can monitor transaction approvals and behavior before users act.
Wallet drainers are a particularly common attack vector. Web3 Antivirus recorded 15,530 suspicious approvals across 11,908 wallets in January, leading to $4.25 million in losses. These attacks typically exploit malicious transaction approvals, emphasizing the importance of detection before signatures are confirmed.