A wallet created for a tutorial may look disposable but its keys can remain a security and reputational risk long after the video is finished.
What stands out in BNB Chainโs disclosure is not the unauthorized token itself. It is that a demo seed phrase allegedly survived the employeeโs departure and the address later carried enough perceived legitimacy to create confusion.
Security offboarding cannot stop at disabling email and repository access. It should include test wallets, API keys, deployer addresses and every credential created during demonstrations.
Should public blockchain teams maintain a visible registry showing which addresses are active, retired or used only for testing?
A wallet address was previously created by a former employee, which they then used to generate a token, as part of a video tutorial. That individual is no longer with the company as part of this incident.
The individual retained unauthorised access to the associated seed phrase after their departure and used it to generate a new private key.
We are now aware that the same address is being used independently in connection with a new meme token. BNB Chain did not create, authorise, promote or participate in the creation of this token and has no control over the token or wallet address. These are not affiliated with or endorsed by BNB Chain.
We are pursuing legal action against the former employee and cooperating with relevant authorities on this matter.