Is BingX safe? The honest answer, including the parts that cost me money | RebateMax
Back to Blog

Is BingX safe? The honest answer, including the parts that cost me money

July 27, 2026The operator of RebateMax

Posted by the operator of RebateMax

I earn commission when you register on BingX through my link. That is a direct financial interest in you concluding that BingX is safe.

Most articles ranking for this question are written by people in exactly the same position and don't mention it. So here is the arrangement: I am going to tell you what makes BingX a reasonable venue and what should worry you, including one thing that is live right now and may mean you shouldn't register at all depending on where you live.

If that costs me signups, it costs me signups. A referral business built on people not reading the risk section is a bad business.

This post is the risk register.

What happened in September 2024

BingX was hacked. This is the most important fact in any assessment of the exchange and it does not belong in a footnote.

On 20 September 2024, around 4am Singapore time, BingX's technical team detected abnormal network access to its hot wallet infrastructure. Withdrawals were suspended within roughly an hour.

The loss estimates never converged. PeckShield first reported around $13.5 million, then revised sharply to $43 million. Lookonchain put it near $26 million. Later analysis settled around $44.7 million. Cyvers estimated the figure exceeded $52 million.

The attacker hit wallets across at least seven chains — Ethereum, BNB Chain, Base, Optimism, Polygon, Arbitrum and Avalanche — through multiple exploit addresses, then swapped the proceeds into more liquid assets and moved them between networks to complicate tracing.

The structural detail matters more than the number. Security firm Halborn noted that compromising hot wallets across that many chains at once suggests BingX was holding copies of its private keys in a single centralised repository. The alternative — multi-signature or multi-party computation wallets, where no single point of access controls the funds — distributes that risk.

If Halborn read it right, this wasn't bad luck. It was an architectural decision that turned one breach into seven.

BingX was not alone that year. DMM Bitcoin, WazirX and Indodax were all compromised through hot wallets in 2024, several incidents attributed to the North Korean Lazarus Group.

What they did about it

Credit where it's earned: the response was fast.

Withdrawals for major assets — USDT, USDC, BTC, ETH, TRX, XRP, SOL — resumed within about 24 hours. Deposits followed inside 48. BingX committed to covering user losses in full and said the affected funds were a small fraction of total assets, with the majority in cold storage. SlowMist was brought in to investigate, law enforcement was engaged, and the wallet system was rebuilt.

Since then BingX publishes proof-of-reserves attestation using Merkle tree verification, updated twice monthly, and maintains a shield fund reported at $150 million.

How much weight should that carry? Some. Not unlimited.

Proof of reserves shows assets at a moment in time. It does not show liabilities comprehensively and it cannot tell you whether the wallet architecture that failed in 2024 is genuinely fixed. A shield fund is a promise backed by a balance sheet, not an insurance policy you can file a claim against. Both are better than nothing. Neither is a guarantee.

The honest summary: BingX got hit hard, moved quickly, made users whole and has visibly invested in not repeating it. That is a better record than several exchanges that simply disappeared. It is not the same as never having been breached, and anyone telling you otherwise is selling something.

The thing I have every incentive to leave out

Here is the part that is current, affects a lot of readers, and costs me money to publish.

BingX does not appear in ESMA's register of MiCA-authorised crypto-asset service providers. As of early July 2026 it was not authorised to serve clients in the EU or EEA, and no public application had been confirmed.

MiCA's national transition periods ended on 1 July 2026. Regulators ruled out an extension. After that date only CASP-authorised firms may keep serving EU clients — and more than a thousand previously registered firms were still short of full approval when the deadline arrived.

BingX holds national registrations through various entities: FCIS-regulated in Lithuania, FINTRAC in Canada, a FinCEN MSB registration in the US, a listing on Italy's OAM registry. A national registration is not a MiCA CASP authorisation, and after 1 July it is the CASP authorisation that governs EU access.

If you are in the EU or EEA, this is live, not theoretical. Using an unauthorised venue can mean weaker consumer protections and the possibility of restricted access, paused services, or a forced migration mid-position.

The register can lag a recent decision and exchanges sometimes pursue authorisation quietly through an EU entity, so this may resolve. But as things stand: check BingX's current ESMA status yourself before registering anywhere, and weigh a MiCA-licensed venue seriously.

I would rather you traded somewhere licensed than registered through my link and lost access with a position open.

Where BingX isn't available at all

BingX restricts access in more than twenty jurisdictions, including the United States, United Kingdom, Canada, mainland China and Singapore, alongside sanctioned regions. It operates in 160-plus countries otherwise. Derivatives specifically are blocked in the US, UK, China and Canada.

If you are in a restricted jurisdiction the question is moot. Attempting to route around geographic restrictions puts your funds at risk of being frozen with no recourse — that is the standard consequence in the terms of every major exchange, not a scare story.

What "safe" actually means for an exchange

Strip the marketing and there are four separate risks. Venues tend to be strong on some and weak on others, and the reviews that give a single verdict are averaging things that shouldn't be averaged.

Custodial risk. They hold your keys. Every centralised exchange has this. Cold storage ratios, proof of reserves and shield funds reduce it. Nothing eliminates it.

Security risk. Can they be breached? BingX has been, once, materially, in 2024. Zero breaches is better. How a venue behaves during one is the next best signal, and BingX's behaviour was decent.

Regulatory risk. Can they legally serve you next year? This is BingX's weakest area right now, specifically in the EU. It is also the risk most reviews skip, because it's boring until it isn't.

Operational risk. Withdrawal delays, support quality, sudden policy changes. Ordinary, and worth reading recent user reports on rather than taking anyone's word.

An exchange can be excellent on liquidity and product and still fail you on the third one.

What I actually do

Since I'm asking you to weigh this, here is my own posture. It applies to any exchange, not just this one.

Don't custody long-term holdings anywhere you trade. Trading balance on the venue, savings in self-custody. This single rule survives every exchange failure of the last decade and would have protected users of every collapsed platform you can name.

Size the exchange balance so a total loss is survivable. More useful than trying to rank which venue is least likely to be hacked, because the ranking changes and the exposure is the part you control.

Check jurisdiction and licensing before funding, not after. Especially in the EU through 2026.

Turn on every security control offered. Authenticator-based 2FA rather than SMS, withdrawal address whitelisting, anti-phishing codes. Most account losses are not exchange breaches. They are individual accounts taken through reused passwords and SIM swaps.

So — is it safe?

BingX is a large, established venue with real liquidity, more than ten million users and a genuinely good product in places. It was breached in 2024, handled it competently, made users whole and has invested in the infrastructure since. It is also, as things stand, not MiCA-authorised.

Outside the EU, in a supported jurisdiction, holding only trading capital on the exchange: the risk profile is comparable to its peer venues. Reasonable.

In the EU or EEA: check the current ESMA register before registering anywhere, and take a MiCA-authorised alternative seriously.

In the US, UK, Canada, China or Singapore: it isn't available to you, and that's the end of the analysis.

Whatever you conclude, conclude it from the primary sources. BingX publishes its proof-of-reserves page and its restricted-jurisdiction list. ESMA publishes the CASP register. Those take ten minutes to check and they are worth more than any review, including this one.


Next in the series: BingX versus Bybit — the fee schedules side by side, and which venue suits which kind of trader.

Disclosure: RebateMax earns affiliate commission on trading fees generated by accounts registered through this link and returns 50 of those 60 commission points as a lifetime discount. The full arithmetic is here. This post is general information, not financial advice, and nothing here is a recommendation to trade or a guarantee about any venue's solvency or security. Licensing status changes — verify it yourself before funding an account.

Register on BingX with code PI6DMC2R

Lifetime 50% fee rebate. Applied at the exchange level.