The first real thing to do after opening an account isn't buying — it's locking the account down. That runs against instinct: most beginners, the moment they finish signing up, head straight for the market page to figure out their first buy. But if you actually rank things by importance, what to buy doesn't make the top three. A bad buy costs you one trade. An account that gets taken over costs you the balance and the account both. The first you can recover from over time; the second is usually one-and-done, and irreversible.
Account security takes a careful pass through the current settings page and another review after a phone, number or address changes. This guide explains two-factor authentication, anti-phishing codes and withdrawal whitelists, then provides a checklist. The exact options available are the ones shown in your account.
1. Why security comes before picking a coin
The logic is plain: security is your floor, returns are your ceiling. If the floor isn't solid, a high ceiling means nothing.
- The downside isn't symmetric. Misread the market and you lose part of your capital, with a chance to earn it back. Get your account hacked and your coins moved out, and it's usually all of it, with no way to recover. Once an on-chain transfer confirms, there is no "undo" button.
- Attackers don't care how much you know. Phishing, credential stuffing, fake support — these are cast wide. They don't pass you by just because you're new or your balance is small. If anything, beginners with no defenses set up are the easiest mark.
- The cost is basically zero. These settings don't cost money and don't get in the way of normal trading. They're purely a lock on your account. There's no reason not to do them.
So even if you haven't decided what to buy today, it's worth finishing this page first and getting the locks on. We'll start with the most important one — two-factor authentication.
2. Two-factor auth: why an authenticator app beats SMS
Two-factor authentication (2FA) means that when you log in or withdraw, you enter a one-time code on top of your password. Even if your password leaks, a password alone won't get anyone in. Binance generally supports a few 2FA methods, but they differ a lot in how secure they are:
- An authenticator app (such as Google Authenticator, or Binance's own Authenticator) — the first choice. It generates a six-digit time-based code locally on your phone, never touching the network or your mobile carrier. Without your phone, no one gets the code.
- SMS codes — usable, but not your main line. An SMS code travels over the carrier's network, which exposes it to SIM-swap attacks (someone re-issuing your number) or interception. It's better than nothing, but clearly weaker than an authenticator.
The setup is usually under the "Security" settings of your account. For the exact steps and supported methods, go by the security-settings guidance in the Binance official help center. For how two-factor auth works in general, see the Wikipedia entry on multi-factor authentication.
3. Anti-phishing code: how to set it, what it stops
An anti-phishing code is a string you define in account security. Once enabled, it can be an additional signal on some Binance emails. Which messages include it and where it appears depend on the current official instructions and your account setting.
What does it stop? Fake emails. Scammers often use phishing to forge "official Binance" emails with alarming subject lines ("account anomaly," "verify immediately") to lure you onto a phishing site to enter your password. But the scammer doesn't know your anti-phishing code, so a fake email either won't carry the string at all, or will fill in the wrong one. So:
- A matching code is only an additional signal; still verify the sender domain, link destination and any matching account notice;
- If the code is missing or wrong, do not use the email's links. Open the official site from your own bookmark and verify separately, without treating that single signal as final proof.
Phishing runs a long line, and fake emails are just one link in it. We've written a separate piece on the matching fake apps, fake support, and fake airdrops — how to spot a fake Binance app, fake support, and fake airdrops — and it's well worth reading alongside this one.
4. The withdrawal address whitelist
The withdrawal whitelist (address management / withdrawal address whitelist) is the last and the hardest gate. Once it's on, your coins can only be withdrawn to addresses you've added and verified in advance — any other unfamiliar address simply can't receive a withdrawal.
It guards against the worst case: if your account gets controlled, and the attacker wants to move coins to an address of theirs, that address isn't on your whitelist, so the transfer gets blocked. It's like saying "even if a thief gets into the house, the door only lets things be carried to the few places you named."
- Add the addresses of wallets you actually own. Your own wallet, say, or another account you've confirmed is safe.
- Turn on "only allow withdrawals to whitelisted addresses." The whitelist only works as a lock once that switch is on.
- Adding a new address usually has a cooling-off period or extra verification. That's a good thing — it gives you time to react, so don't begrudge the friction.
5. Devices, authorizations, and API management
Beyond the three main lines above, a few spots are worth checking periodically:
- Device and login management. Your security settings show which devices have logged into your account. See a device you don't recognize, and immediately "remove / sign out that device" and change your password. The same settings are also a common reason you get locked out yourself — not being able to log in after switching phones is usually the device check, and when Binance won't let you log in works through the four causes in order.
- Authorized third-party apps. If you've authorized any third-party tool to access your account, check periodically and revoke anything you no longer use or that looks suspect.
- Be especially careful with API keys. An API is the key for programmatic trading, and it carries broad permissions. Beginners basically have no use for it — if you don't need it, don't create it. If you really must, turn off the "withdraw" permission and bind an IP whitelist; a leaked key is the same as handing over your account.
6. A few habits that matter more than any setting
Switches are static; habits are what keep you safe. No amount of settings can stop you from opening the door yourself:
- Only log in through the official entry you saved yourself. Go in from a browser bookmark or the official app — don't click links in emails, texts, or ads.
- Use a unique, strong password. Don't reuse your exchange password on other sites — that's what guards against credential stuffing: a leak elsewhere taking this account down with it.
- Codes, passwords, seed phrases — never tell anyone. No legitimate process will ever ask you to read these out to support or anyone else. This one is the bottom line; commit it to memory.
- For large, long-term holdings, consider self-custody. Keep only what you'll use soon on the exchange; with a self-custody wallet only you hold the private key. For the why and the how, see the piece on whether an exchange might collapse.
7. An account-security checklist
Tick off the items below one by one. If you can do all of them, you have completed the main account protections covered in this guide:
- An authenticator app is set as your primary 2FA, with SMS only as backup;
- The authenticator's backup key is copied offline and stored safely;
- An anti-phishing code is set, and you check it on every email;
- The withdrawal address whitelist is on, allowing only whitelisted addresses;
- Your account password is unique and strong, not reused on other sites;
- You periodically check login devices and third-party authorizations and clear out anything suspect;
- You don't create an API without need; if you do, withdrawal permission is off and an IP is bound;
- You keep in mind: codes, passwords, seed phrases — never to anyone.
These settings do not require programming, but they do require reading the prompts and storing recovery information safely. Work through the current security page, then review login devices, API permissions, whitelists and recovery methods periodically.
7. FAQ
I'm not getting the code when I log in or withdraw — where do I look?
It depends. With an authenticator app, there's no such thing as "not receiving" a code — it rolls over locally on your phone. If it won't pass, it's usually because your phone's clock is out of sync with the server; go into the authenticator app's settings and run a one-time "time correction." With SMS codes, first check your signal and any blocking app, confirm the number isn't barred by your carrier, then use "resend" on the page. SMS is often delayed or dropped — which is exactly why we suggest making the authenticator your main line and SMS only a backup.
I got a new phone — how do I move my 2FA over from the authenticator?
It comes down to whether you kept that backup key before switching. If you did, install the authenticator on the new phone and re-add the account using the backup key (or the original QR code), and the codes come back. If you didn't, and the old phone is gone, your only path is Binance's official 2FA reset/recovery flow, which usually requires re-verifying your identity and takes some time. That's why this piece keeps stressing: copy the backup key somewhere offline the moment you set up the authenticator.
I suspect my account is compromised — what do I do first?
Move fast, in order: change the login password first, then sign out of all devices and reset two-factor auth; next check your withdrawal whitelist and API for any unfamiliar address added or a key with withdrawal permission created behind your back, and delete it; if your coins are still there, move them to an address you've confirmed is safe. Do all of this by reaching support through the official bookmark you saved yourself — never a link or contact a stranger gave you.
If I forget or want to change my anti-phishing code, does that hurt my account security?
The anti-phishing code is not a login credential. If you forget or change it, use the current account security page to review or reset it. Treat a matching code as one signal only, and still verify the sender, link destination and account notice through a site you opened yourself.
Do I have to turn on both SMS and an authenticator for 2FA?
You don't have to run both, but the authenticator must be your main line. SMS alone is weaker (SIM-swap risk); the ideal setup is authenticator as primary with SMS as backup, so you have a fallback if something happens to the phone holding your authenticator. For exactly which combinations are supported, go by the options on Binance's security settings page at the time.
Use the strongest two-factor options currently offered to your account and keep recovery keys offline. Treat an anti-phishing code as an additional signal, not proof. A whitelist does not replace checking every address. Give verification codes, 2FA backup keys, seed phrases and private keys to no one, and review the settings again after device or account changes.