BNB Chain has initiated legal action against a former employee who used a seed phrase from an old instructional video to launch an unauthorized meme token, the protocol disclosed on August 1, 2026. The incident highlights a critical security gap in offboarding cryptographic keys and marks the third insider-linked token controversy within the Binance ecosystem since early 2025.
The wallet at the center of the dispute was originally generated on camera for a BNB Chain tutorial. While the company believed the address was retired after filming, the ex-employee retained the seed phrase and later reconstructed the private key to deploy a token called ASTEROID from that exact address. On-chain analytics firm Lookonchain reported that the individual used four fresh wallets to acquire 796.7 million ASTEROID tokens—roughly 79.67% of the supply—for about $10,000, then sold 718.8 million of them for 1,103 BNB, netting a profit of approximately $628,000.
BNB Chain stressed that it never created, endorsed, or promoted the token and has no control over the wallet or the asset. Because seed phrases exist outside centralized control, revoking access is impossible; the only effective defense is never using a live wallet as a disposable teaching prop and formally retiring any address that appears in public material. The protocol said it is cooperating with law enforcement, though it did not disclose the jurisdiction, the token’s ticker other than the reported name, or the individual’s identity.
The episode follows a March 2025 case in which a Binance Wallet team member front-ran a token generation event using knowledge from a former BNB Chain role, and a December 2025 incident where an employee promoted a self-made meme coin from the official @BinanceFutures account, peaking near a $6 million market cap. In response to the latest breach, Binance co-founder Changpeng Zhao labeled the former employee “basically a scammer” and told users to “Stay SAFU.” The BNB Chain team emphasized that the address’s history does not validate tokens deployed from it and urged users to verify contract addresses only through official channels.