Binance Account Security: 2FA, Anti-Phishing and Whitelists
The four settings worth turning on before your first deposit, why SMS two-factor is the weakest option, and how withdrawal whitelisting stops the worst outcome.
Exchange accounts are not usually broken into. They are logged into, with credentials the attacker already has, from a session the user handed over.
That changes what security means here: the settings that matter are the ones that fail safely when your password is already compromised. There are four of them, they take about ten minutes in total, and they should be done before any money arrives.
1. Two-factor authentication
Turn it on with an authenticator app rather than SMS.
SMS codes are delivered to a phone number, and phone numbers are transferable. SIM-swap attacks — where someone convinces a mobile operator to move your number to their device — are a standard technique against crypto accounts specifically, because the payoff justifies the effort.
An authenticator app generates codes on the device itself. There is nothing to intercept and no operator to social-engineer. A hardware security key is stronger still where supported.
- Install an authenticator app on a device you control and keep.
- Enable app-based two-factor in Binance's security settings.
- Store the recovery codes offline — on paper is fine, in the same password manager as the password is not.
- If SMS two-factor is already enabled, disable it once the app method works.
- Test it once by logging out and back in, before you deposit anything.
Losing access to the authenticator without recovery codes means an identity-verification recovery process that takes days. Write the codes down at the moment you enable it, not later.
2. Anti-phishing code
This is the highest-value setting relative to the effort it takes, and most people have never heard of it.
You choose a short phrase, and Binance includes it in every genuine email it sends you. Phishing emails — which copy Binance's design precisely and are frequently indistinguishable otherwise — cannot contain it, because whoever sent them does not know it.
From then on, an email without your phrase is fake, regardless of how convincing it looks. That is a check you can do in one second, every time, with no judgement required.
3. Withdrawal address whitelist
This is the setting that determines how bad the worst case gets.
With whitelisting on, funds can only be withdrawn to addresses you approved in advance, and adding a new address triggers a waiting period before it can be used. An attacker who has your password, your session and even your two-factor codes still cannot move funds to their own address immediately — and the delay is exactly the window in which you notice and act.
Without it, a compromised account is emptied in one transaction to an address you have never seen, and the transaction is irreversible.
- Enable the whitelist before your first withdrawal, not after.
- Add only addresses you control and expect to reuse.
- Expect a security delay when adding a new one — that delay is the feature.
- Review the list periodically and remove addresses you no longer use.
- Combine it with two-factor: the two together cover almost every realistic attack.
4. Session and device hygiene
Binance's security settings list every device and active session on the account. Read that list once and then occasionally.
Anything you do not recognise should be terminated immediately, followed by a password change and a two-factor reset. Sessions persist far longer than people expect, and an old session on a device you sold or lost is a live credential.
The same section carries API key management. If you have never created an API key, there should be none listed — a key you did not create is the single most serious finding possible, because keys can trade without triggering a login alert.
If you do create API keys for a bot or a portfolio tracker, restrict them to the permissions actually needed, bind them to an IP address, and never enable withdrawal permission.
How accounts actually get taken
Understanding the common paths makes the settings above feel less abstract.
Phishing is the dominant route. A convincing email or advert leads to a login page that is not Binance, you enter your credentials and your two-factor code, and the attacker relays both to the real site within the code's validity window. The anti-phishing code defeats the email version of this; bookmarking the real site and never navigating from a link defeats the rest.
Fake support is the second. Nobody from Binance will contact you first on Telegram, Discord or WhatsApp. Support conversations start from inside the app, initiated by you.
Malicious approvals and clipboard malware matter more for self-custody wallets than exchange accounts, but the habit that protects against them — verifying the first and last characters of any address you paste — is worth having everywhere.
SIM swap targets SMS two-factor specifically, which is the reason the first section says what it says.
What no security setting protects you from
Being clear about the limits matters as much as the checklist.
None of these settings protect you from your own trading decisions, from a leveraged position being liquidated, or from an asset falling in value. Those are not security events, and no configuration prevents them.
Nor do they change the fundamental position that assets on any exchange are held by that exchange. For amounts you intend to hold long term, self-custody in a wallet whose keys you control is a different risk profile — one with its own failure modes, primarily the permanent and unrecoverable loss of a seed phrase.
The ten-minute checklist
In order, before the first deposit.
- Enable app-based two-factor authentication and store the recovery codes offline.
- Set an anti-phishing code.
- Enable withdrawal address whitelisting.
- Review active sessions, devices and API keys; terminate anything unfamiliar.
- Bookmark the real Binance domain and use only that bookmark from now on.
- Make a small test deposit and withdrawal to confirm the whole path works while the stakes are low.
SAM210826
The code can only be entered while you create the account. It costs you nothing and cannot be added later.
No referral code has been added for this exchange yet.
Get in touch: contactmail.bsam@gmail.com
No referral code has been added for this exchange yet.
Get in touch: contactmail.bsam@gmail.com
No referral code has been added for this exchange yet.
Get in touch: contactmail.bsam@gmail.com
No referral code has been added for this exchange yet.
Get in touch: contactmail.bsam@gmail.com
Questions about this page
Is SMS two-factor authentication good enough?
It is better than nothing and worse than an authenticator app. SIM-swap attacks specifically target phone-based two-factor on crypto accounts.
What does an anti-phishing code do?
It adds a phrase you chose to every genuine Binance email. Any email without it is fake, which turns a judgement call into a one-second check.
Why is withdrawal whitelisting important?
It limits withdrawals to addresses you approved in advance and imposes a delay on new ones, so a compromised account cannot be emptied instantly to an unknown address.
Will Binance support ever contact me first?
No. Support conversations start from inside the app, initiated by you. Anyone messaging you first on Telegram, Discord or WhatsApp is not Binance.
Should I keep long-term holdings on an exchange?
Assets on an exchange are held by that exchange. Self-custody is a different risk profile with its own failure modes — principally the permanent loss of a seed phrase.
Fee rates on this page were checked on 2026-08-21 against the exchange's official fee schedule. Rates can change without notice.