Zhenku
Guard · Repel · Emergency

Binance Account Hacked: What to Do in the First 10 Minutes

Zhenku Editorial · Cheng Mo Updated 2026-07 About 17 min
Cover: what to do when your Binance account is hacked

The moment you realise something's wrong, your head goes blank — a login alert you don't recognise, a withdrawal you never made, or worse, the password's been changed and you can't even get in. The more you panic, the more likely you are to do things in the wrong order and burn the few minutes that should've gone to stopping the bleeding. This lays out what to do in the first ten minutes, and in what order, then says out loud the thing a lot of articles dodge: if the coins are really gone, can you actually get them back? The honest answer depends on the specifics — I'm not going to sell you a fairy tale.

First, figure out which situation you're in

Before you touch anything, spend ten seconds working out which bucket you're in — the next moves are completely different for each:

Don't do this firstA lot of people's first instinct is to search for a "Binance support phone number" or "recover my account" and click the top result — which is exactly the second net the scammers have laid out. Binance has no human phone line that will proactively help you "recover coins"; every legitimate entry point is inside the official app or website after you log in. Steady yourself first, and don't click blindly.

The first ten minutes, in this order

The order below is arranged as "stop the loss first, deal with the aftermath later." If you can still log in, work down from step one; if you can't, jump straight to the next section.

1) Change your login password immediately

Your first cut takes out the key the attacker most likely holds — the login password. Change it to a strong password that's brand new and never used anywhere else. The point of this step: if they got in via credential stuffing or a leaked password, changing it shuts that door on any entry point outside the current session. Note that changing the password on its own may not immediately kick out sessions the attacker is already logged into, which is why the next step follows right on.

2) Emergency-freeze the account

Binance has an emergency freeze / disable account entry point for quickly suspending sensitive actions (login, trading and withdrawals get restricted) when you suspect a breach. This is the single most important move of the first ten minutes — it blocks the "keep moving coins out" path before you've even started going through things item by item. Once frozen, the account goes into a restricted state, and you follow the official prompts to verify and unfreeze later. The exact name and location follow whatever Binance's official page currently shows, and you really should know where it lives ahead of time (which is exactly why we keep saying: learn the doors first).

Worth rememberingIn the stop-the-bleeding order, "freeze" often ranks above "change password" — because it cuts off the withdrawal artery directly. If the freeze entry point is quicker to find on your screen than the password one, freezing first and changing the password after is completely reasonable.

3) Revoke every API key

If you've ever created API keys for copy-trading, quant, or bookkeeping tools, this is the most overlooked and most dangerous back door when you get hacked. The attacker may not have logged into your account at all — instead they got hold of an over-privileged API key that lets a program place orders and withdraw on your behalf. So go into API management and delete every key, no exceptions — don't sit there sorting out which one is the problem; in a compromised state, wiping them all is safest, and you can rebuild what you need once things are secure. More in API key security and permissions.

4) Check and boot unfamiliar login devices

Go into device management / login activity and look over which devices and sessions are currently online. Remove or log out every device and session that isn't you. This closes the "window they've already climbed through" — changing the password alone sometimes leaves their live session intact. While you're at it, note the time, IP and device details of the unfamiliar logins, and screenshot them as evidence. Where to look and how to kick them, see device management and unusual logins.

5) Go through your other security settings for tampering

Once inside, attackers often quietly rewire your security settings to hold onto control long-term: swapping out your bound 2FA, changing your anti-phishing code, adding their own withdrawal address to the whitelist, changing your email or phone number. Check each one —

6) Contact official Binance support and file a ticket

Once the bleeding's stopped, file a ticket through the support entry point inside the official app or website, explaining the account was compromised and listing the anomalies you saw (unusual login times, the transaction ID / TxID of any odd withdrawal, settings that were altered). Hand over the screenshots and notes you took earlier. If there was an unauthorised withdrawal, providing the TxID matters — on the off chance the assets are still parked at some stage inside the platform, support may be able to help intercept them. Do this through official channels only, and don't trust any "support agent" who reaches out to you.

When you're panicking, the scariest thing is skipping a step. We've turned the whole thing above into a hacked-account response tree: it walks you through the next action based on your actual situation (can you still log in, are there odd withdrawals), so you just follow the taps instead of memorising the order on the spot.
Open the hacked-account response tree →

If you're already locked out

Password changed, 2FA swapped, email tampered with — you've been booted out of your own account. At this point the only proper path is Binance's official account-recovery / appeal flow:

Verify it's officialTo judge whether a "Binance" message is real, cross-check three things: the anti-phishing code, the sender domain, and the wording — read how to confirm a "Binance" message is genuine, or run it through the phishing message checker. When you've been hacked, spotting fake support matters more than anything.

Can you get it back? Straight answer

This is what everyone cares about most — and what scammers exploit most. Let me lay out the reality so you can make your own call:

If the coins are still inside Binance (not yet withdrawn, or the withdrawal is still in processing / risk-control), there's some chance. If you froze fast and reported early, support may be able to hold it inside the platform. That's the entire point of racing the clock in those first ten minutes.

If the coins have already been withdrawn to an external on-chain address, realistically, they're mostly gone. The reasons are hard and unforgiving:

So the honest conclusion is: do the stop-the-bleeding, the appeal and the police report, because doing them is what gives you that "maybe" — but don't pin your hopes on the word "recover." Anyone or any outfit telling you "pay a service fee and we'll get your coins back for you" is almost certainly a scammer — the second harvest reaped off victims.

In one lineRecovery is a long shot; cutting losses and hardening are things you can definitely do. Put your energy into "how do I keep the remaining assets safe" and "how do I not go through this again" — that's more useful than agonising over the coins that already went on-chain.

Does reporting to police help

Report it, but manage your expectations.

The real value of reporting is leaving a formal case record and a receipt. That receipt carries weight later when you're pursuing a platform appeal, a possible insurance claim, or a legal process; and when the amount is large or organised fraud is involved, the police may open a case and coordinate on the investigation.

But be clear about the limits too: crypto is cross-border, anonymous and irreversible, so the share the police can actually recover isn't high, and the process is slow. Think of reporting as "putting this on the official record and keeping future options open," not "report it and get the money back."

When you file, bring as much as you can: the TxID of the unauthorised transaction, the attacker's address, the timeline, your ticket history with official Binance support, and your own account details. The fuller the file, the easier it is to open a case.

"The police" is the wrong address in most of the English-speaking world

In England, Wales and Northern Ireland, fraud doesn't go to your local force at all — it goes to Action Fraud, the national reporting centre, on 0300 123 2040 or through its online tool. Scotland is the exception and goes to Police Scotland directly. Canada has the Canadian Anti-Fraud Centre; investment fraud should also go to your provincial or territorial securities regulator. Australia has ReportCyber, which replaced the older ACORN system, with ASIC as the second address for crypto-asset misconduct.

Walking into a local station and asking them to take a crypto report will usually get you sent to one of those anyway, a day later — and a day matters. Which desk takes your report, country by country, what to have ready before you start the form, and why the American one everybody links to is no use to you.

Watch for the second scam: fake "recovery" support

This gets its own section because it cuts so deep. A victim is panicking and grasping at any hope, and scammers zero in on exactly that state of mind:

Remember one iron rule: official Binance will never DM you first, never ask for your password / verification code / seed phrase, and never make you pay before "recovering" anything. Every legitimate action happens inside the official app or website you log into yourself. Being hacked is bad enough — don't let yourself get cut a second time.

Once the dust settles: review and harden

You've got control back and saved the remaining assets — don't rush to close the book. Spend some time working out how they actually got in, or you'll patch up and still leak again:

Find the root cause, fix the right thing, and getting hacked won't have been for nothing. The full settings list is in the complete account security checklist, or just run the account security check-up, tick a few boxes, get a score for your account as it stands, and see which defences are still missing.

How to not go through this again

Hardening after the fact and prevention before it are really the same checklist. Set these all up in one go and you block the vast majority of the ways accounts get taken:

  1. Use an authenticator app or security key for 2FA, with SMS as backup only — this one blocks the most attacks.
  2. Turn on a withdrawal address whitelist and add your usual addresses ahead of time. This is the fallback insurance that means "even if they log into your account, they can't move the coins."
  3. Keep your login password unique and unreused, paired with a password manager.
  4. Set an anti-phishing code, and build the habit of "any 'Binance' email without the code is fake."
  5. Grant API keys minimum permissions only, and delete unused ones promptly.
  6. Know where the emergency freeze and hacked-account appeal entry points are — when it really happens, those ten seconds are worth a lot.

Treat this as something to finish on the day you register, not a fix after things go wrong. One full guide covers every layer in depth: the defences you should turn on from day one.

FAQ

My Binance account was hacked and the coins were moved out. Can I get them back?

Honestly, in most cases no. An on-chain transfer is irreversible once confirmed, so the main thing Binance can do is freeze whatever's still inside the platform and cooperate with the investigation. Once coins have left for an external address and been obfuscated, there's almost no realistic way to claw them back. Do the right things anyway — file an official appeal, keep evidence, report to police if warranted — but don't pin your hopes on recovery.

What's the very first thing to do when I notice the hack?

If you can still log in: change your login password right away, then use emergency freeze to pause the account, revoke every API key, and boot any unfamiliar login devices. If you're already locked out (the password was changed), go straight to Binance's official account-recovery/appeal flow — don't mess around on a spoofed page or with so-called support. The core of the order is stop the bleeding first, appeal second.

Is it worth reporting stolen crypto to the police?

Worth doing, but manage your expectations. A report leaves a formal record, and in some cases police can coordinate with the exchange or across borders; but the cross-border, anonymous, irreversible nature of crypto keeps the real recovery rate low. The case receipt is useful material later for a platform appeal or legal process, so filing is still advised.

Someone says they can recover my coins for a service fee — can I trust them?

Almost always a scammer. This is a second-round scam that targets victims specifically. Ignore anyone who says "pay first, recover later" or asks for your seed phrase / private key / verification code to "verify your identity." Official Binance won't DM you first, and every legitimate action happens inside the official app or website you log into yourself.

What if I can't find these entry points?

Binance's interface and feature names change from time to time. This article is about the order of actions and what each step does; the exact entry points follow whatever Binance's official page currently shows. If you can't find one, search the official help centre for terms like "emergency freeze," "account recovery," or "API management."

CM
Cheng Mo · Zhenku Editorial

"Cheng Mo" is a pen name, not a licensed expert. What we do is take Binance's official security mechanisms and published rules and explain them in an order an ordinary user can follow, walking through the flow ourselves to check where we can. This article isn't investment advice, and what we've written about whether hacked funds can be recovered is the honest reality, not a guarantee; spot something wrong, and please tell us via corrections.

Sources

  • Binance official help centre · entries on account security and handling theft (binance.com/en/support, refer to the current official page)
  • Binance security page · account protection and emergency-freeze notes (binance.com/en/security)