Binance Founder CZ: Withdrawals Should Be Suspended First in Case of Incidents
Binance founder Changpeng Zhao's public principle is that exchanges should first suspend withdrawals after a security incident, investigate how hackers gained access, identify which devices were compromised, and confirm safety before resuming operations. After the Bybit hack, he wrote: "The situation is difficult to handle; as a standard precaution, it may be best to suspend all withdrawals first; $1.5 billion is already enough to cause panic, so it’s better to err on the side of safety." He added that there is no absolute right or wrong, just a direction based on experience that leans towards safety.
On February 21, 2025, approximately $1.5 billion was drained from a cold wallet at Bybit, marking one of the largest single thefts on record in the industry. The assets included about 401,300 ETH and staking derivatives like stETH, cmETH, and mETH, with on-chain analysis pointing to North Korea's Lazarus group. The attack occurred during what was supposed to be a routine internal transfer: the front end displayed a normal transaction, but a different transaction was actually signed, and the cold wallet used Safe multi-signature. CEO Ben Zhou assessed that the internal system and hot wallet were not compromised, chose to continue withdrawals, and stated that even if losses could not be recovered, the platform still had the ability to pay.
With the withdrawal channel still open, a bank run ensued. CoinDesk reported that the theft combined with the "bank run" caused the platform's related wallet assets to drop from about $16.9 billion to approximately $11.2 billion, totaling over $5.5 billion in outflows; another statistic tracked assets dropping from nearly $17 billion to about $10.8 billion within three days. Zhou stated that within ten hours, the platform experienced the highest number of withdrawal requests ever, exceeding 350,000, prioritizing retail users and imposing tiered restrictions on institutions, while also borrowing Ethereum liquidity from peers. He later said that if the withdrawal system or hot wallet had been compromised, he would agree to suspend withdrawals; this time it was a cold wallet, and the remaining internal parts were confirmed safe by a security company before he dared to keep operations running. CZ's suggestion was seen about half an hour later while he was live streaming.
CZ categorized this incident into the same pattern: Bybit, Phemex, WazirX, and others have all experienced significant withdrawals from multi-signature "cold storage." On May 7, 2019, Binance's hot wallet was drained of 7,000 BTC, worth about $40 million at the time, with hackers obtaining a large number of user API keys and two-factor codes, allowing them to bypass pre-withdrawal risk controls, which were later blocked by post-monitoring. Binance immediately suspended deposits and withdrawals while trading continued, using the SAFU user security fund to fully cover losses, and resumed operations about a week later after a comprehensive security audit; CZ later stated that net inflows exceeded net outflows upon reopening. He emphasized that at the time, it was not 100% certain whether it was a hacker, a malfunction, or user operation, so they initially labeled the withdrawal server as undergoing unscheduled maintenance.
The industry's division of labor unfolded simultaneously during the incident. ZachXBT tracked the stolen ETH split into dozens of addresses, while Tether, Circle, and others assisted in freezing some outflows; Bybit later stated that it had recovered and frozen approximately $78.9 million in total and filed lawsuits against North Korea and Lazarus. The absence of a publicly confirmed second wave of attacks on Bybit's hot path does not mean the entry point has been clarified. CZ wrote "suspending operations for a week to conduct checks" into his operational manual, while Ben's judgment was to "not suspend operations to withstand the bank run"; both manuals are competing for the same issue: whether the withdrawal button is a risk control switch or a credibility switch.
In market mechanisms, buyers are users wanting to immediately retrieve their coins and market makers wanting to see proof of solvency; sellers are exchanges that must prove their hot wallets are still intact amid panic. The event was driven by a fake interface tricking signatures from the cold wallet. Funds surged from user balances to on-chain autonomous addresses, then flowed back into the withdrawal queue through peer borrowing. Those benefiting are platforms that can use SAFU or reserves to withstand net redemptions and frame suspensions as professional actions; those under pressure are platforms that choose not to suspend operations and trade liquidity for time, as well as all custodians treating multi-signature cold wallets as "isolated." Regulators have yet to codify "withdrawals must be suspended after a theft" into a unified rule, and pricing power still lies in the founders' immediate statements.
Source: Public Information
ABAB AI Insight
CZ's suggestion is not a technical patch but a public relations shield offered by the industry leader to competitors. In 2019, he suspended operations for a week and used SAFU to cover losses, establishing "suspend first, investigate later" as a reference precedent; when Bybit faced issues, his public call to suspend effectively shifted part of the moral responsibility for a potential second wave of attacks away from Ben. Ben's refusal is equally quotable: being tricked into signing a cold wallet does not mean the hot path has been compromised, and suspending withdrawals would be interpreted as a liquidity crisis. Both are trading the same commodity—user trust in the withdrawal button.
The capital path involves reserves and interbank borrowing, not equity stories. Bybit used reserves and temporary borrowing to handle 350,000 withdrawal requests, while Binance used SAFU to convert $40 million in user losses into platform costs. Whoever can organize stablecoins and ETH within 24 hours can turn a bank run from a death spiral into a stress test. Lazarus wants mixable ETH, users want retrievable withdrawals, and founders want public records of "I am leaning towards safety" or "I am not bankrupt."
Analogous situations include traditional banks' emergency suspensions and Mt. Gox's silent withdrawal halt in 2014. Banks have regulatory backing for suspensions, while Mt. Gox had no explanation; CZ aims to establish withdrawal suspensions as a standard action endorsed by the industry leader, while Bybit wants to advertise its solvency through continuous withdrawals. The industry's position remains during a period of custodial expansion: exchanges have multi-signatures and cold/hot separation, but there is no unified right to suspend operations in case of incidents. The same cold storage model of Phemex and WazirX being breached indicates that the problem is not with a single brand but with the signature interface being interchangeable.
Structural judgments belong to the transfer of pricing power before regulatory changes. Those who can suspend withdrawals at the push of a button hold temporary disposal rights over user assets; those who choose not to suspend hand over pricing power to the speed of the bank run. The mechanism is: on-chain theft is irreversible, but off-chain withdrawals can be paused; pausing creates panic, while not pausing exposes a second door. The market price of "safety over experience" equals whose button remains lit the next time a cold wallet is tricked into signing.
ABAB News · Cognitive Law
- The withdrawal button being lit opens the door for a second wave of attacks.
- Suspension is risk control; not suspending is a bet on credibility.
- On-chain theft is irreversible; the only reversible action is whether you allow withdrawals.