First time on Binance? Sign up and lock the account down — all in one read
Follow the six steps to open your account, then set up 2FA, the anti-phishing code, your fund password and the withdrawal whitelist the same day — don't leave the account sitting there wide open.
The guardian's five wards
From setting a solid password to recovering a hacked account, these five wards build up around your account layer by layer. Each one links to its own guide and a self-check tool.
Seal the GateLogin & fund passwords
Login password, fund password, emergency freeze — bolt the first door shut. How weak passwords get cracked through credential stuffing, and why your fund password should never match your login one.
Open the EyesTwo-factor auth (2FA)
How to choose between SMS, an authenticator app, a security key and passkeys; what to do when you switch phones, lose your phone, or travel and can't receive codes. And why SMS is the one method you shouldn't lean on alone.
Verify the WordAnti-phishing code
A secret word shared just between you and Binance — once it's set, any "Binance email or SMS" that arrives without it is fake, full stop. Two minutes to set up, and it stops most phishing attempts cold.
Lock the DoorWithdrawal whitelist & API keys
Turn on the withdrawal address whitelist and, even if someone gets into your account, funds can only move to addresses you've already approved. Give API keys the least access they need and tie them to an IP whitelist, so no script can quietly empty the place out.
Drive Them OffIf you get hacked
What to do in the first ten minutes when it actually happens: change passwords, freeze the account, revoke API keys, check logged-in devices, report to Binance. Whether you can recover the funds and whether reporting it helps — spelled out step by step.