Skip to content
BTCLoading… ETHLoading… BNBLoading…
English

Security: Spotting Fake Sites, Phishing and Account Takeovers

Nearly every crypto theft starts the same way: a convincing page, a message that creates urgency, or a download from the wrong domain. This guide explains how the tricks work and which settings actually stop them.

Updated: crypto phishing · fake Binance site · official domain check · two-factor authentication · withdrawal allowlist
Disclaimer:This is an independent crypto information and navigation site. It is not affiliated with, authorised by, or acting as an agent for Binance, OKX or any other exchange, and it is not an official support channel. Some download and sign-up links on this site are official links that carry a referral code; continuing to the platform through this site may earn this site a commission, which never increases your cost. Crypto assets are highly volatile and nothing here is investment advice.

How fake exchange sites actually work

A phishing site is a copy of a real login page hosted on a domain that looks almost right. The address might swap two letters, add a word like login or support, or replace the dot with a similar character, and it often arrives through a paid advertisement that sits above the real result in a search engine. You type your email and password, the page reports a network error, and your credentials are already gone.

The same pattern appears in mobile form. Sideloaded applications from a link in a chat group ask for permissions a trading app never needs, and the fake support agent who told you to install it then asks for your two-factor code or your wallet seed phrase. Both requests are a confession: legitimate staff never need either, because they can help you without them.

Verify the domain before you type a password

The single most effective habit in crypto is checking the domain before entering anything. Binance's official website is binance.com and nothing else; a hyphenated variant, a different top-level domain or a lookalike spelling is not the official site, regardless of how polished it looks or what a message claims.

You can also use the official-domain checker on this site to test a suspicious address, and install mobile applications only from the links on the official download page or from the official App Store and Google Play listings. There is no legitimate reason for anyone to send you an installation file directly.

Type the domain yourself or use a bookmark you created. Links in messages, advertisements and search results are exactly where fake addresses hide.

Two-factor authentication: pick the stronger option

Two-factor authentication is not a single thing. A code generated by an authenticator application on your own device, and especially a hardware security key, resists phishing far better than a code sent by SMS, which can be intercepted through SIM swapping or read from a compromised phone. Passkeys, where the platform supports them, bind the login to a device in a way that does not involve typing a shared secret at all.

Whichever method you use, save the backup codes offline at the moment you enable it. Recovery codes are the difference between a stressful afternoon and a permanent loss, and they deserve to be printed or stored in a password manager rather than left in a screenshot. Also review active sessions and API keys periodically: an unused key with withdrawal permission is a standing invitation.

Withdrawal allowlists and address hygiene

Credentials can be stolen; an allowlist is what stops the theft from becoming a transfer. When an allowlist, sometimes called an address book with a delay, is enabled, withdrawals can only go to addresses you approved in advance, and adding a new address usually takes effect only after a waiting period. That delay is the point: it gives you time to notice and lock the account.

Address hygiene matters for the same reason. Clipboard malware silently swaps an address the moment you copy it, so always compare the first and last characters of the destination against the address you intended, and send a small test amount the first time you send to a new address. Matching the network label matters too, because sending on the wrong network can make funds unrecoverable.

If you think you have been compromised

Speed matters more than tidiness. Work through the recovery steps in order, and contact support only through the official website, never through a link or phone number someone sent you.

Keep a record of what happened with timestamps, because support will ask, and be wary of anyone who appears in your messages offering to recover funds for a fee. Recovery services that approach first are almost always a second attempt at the same theft.

  1. Log in from a clean device and change your password immediately.
  2. Revoke active sessions, API keys and any connected third-party authorisations.
  3. Re-check your two-factor settings and regenerate backup codes.
  4. Review withdrawal records and contact official support through the official website.
  5. Run a malware scan on every device that has accessed the account.

Red flags worth memorising

Most scams reuse a small set of pressure tactics. Recognising the pattern takes seconds and is worth more than any single tool.

  • Urgency: an account will be closed, a bonus will expire, or funds are at risk within minutes.
  • Secrecy: you are told not to involve official support or to keep the matter private.
  • Off-platform contact: support moves to a personal messaging account.
  • Requests for secrets: password, two-factor code, seed phrase or a remote-screen session.
  • A payment demand before any money is released, including for tax or verification.
  • A domain that is nearly, but not exactly, the official one.

Official-domain checker

Paste a URL to check whether it belongs to the official Binance domain.

Frequently asked questions

What is the official Binance domain?

binance.com is the official domain. Any other spelling, hyphenated variant or different extension is not the official site, even if the design looks identical. Type the address yourself or use a bookmark you created, and check the domain in the browser bar before entering credentials.

Will Binance support ever ask for my password or code?

No. Legitimate staff never ask for your password, your two-factor code or your wallet seed phrase, and they do not need a remote connection to your device to help you. Anyone who requests any of those is attempting theft, whatever their name or avatar suggests.

Is SMS two-factor authentication good enough?

It is better than nothing but weaker than app-based codes or a hardware key, because phone numbers can be taken over through SIM swapping. If the platform supports an authenticator app, a security key or passkeys, use those instead, and store backup codes offline.

What is a withdrawal allowlist and why does it help?

It restricts withdrawals to addresses you have approved in advance, and adding a new address typically takes effect only after a waiting period. If someone steals your login, they still cannot drain funds to their own address, and the delay gives you time to secure the account.

I sent crypto on the wrong network. Can it be recovered?

Sometimes, if the receiving platform controls the destination address and offers a recovery process, but often it cannot be recovered at all. Prevention is the reliable answer: match the network label to the address the receiving platform shows you, and send a small test amount first.

Someone offered to recover my lost funds for a fee. Is that legitimate?

Treat unsolicited recovery offers as fraud. Scammers target people who have already lost money because they know hope is a strong lever. Official support never charges a private fee through chat to retrieve funds, and paying upfront guarantees you lose more.

How often should I review my account security settings?

A quick review on a regular schedule is worth the few minutes: confirm two-factor authentication is still active, check active sessions and API keys, and make sure your allowlist still contains only addresses you recognise. Remove anything you no longer use rather than leaving it in place.

Related pages