Binance Account Hacked: What to Do in the First 10 Minutes
The moment you realise something's wrong, your head goes blank — a login alert you don't recognise, a withdrawal you never made, or worse, the password's been changed and you can't even get in. The more you panic, the more likely you are to do things in the wrong order and burn the few minutes that should've gone to stopping the bleeding. This lays out what to do in the first ten minutes, and in what order, then says out loud the thing a lot of articles dodge: if the coins are really gone, can you actually get them back? The honest answer depends on the specifics — I'm not going to sell you a fairy tale.
- First, figure out which situation you're in
- The first ten minutes, in this order
- If you're already locked out
- Can you get it back? Straight answer
- Does reporting to police help
- "The police" is the wrong address in most of the English-speaking world
- Watch for the second scam: fake "recovery" support
- Once the dust settles: review and harden
- How to not go through this again
- FAQ
First, figure out which situation you're in
Before you touch anything, spend ten seconds working out which bucket you're in — the next moves are completely different for each:
- You can still log in, and the coins are still there: the best case. You have full control and can stop the bleeding yourself. The priority is welding the doors shut before the attacker makes a move.
- You can still log in, but there are already odd withdrawals or orders: stop the bleeding and gather evidence at the same time, and contact official support as fast as you can.
- You're already locked out (password or 2FA changed): you've lost direct control, and the only proper path is Binance's official account-recovery/appeal flow. Don't burn time on any page of unknown origin.
The first ten minutes, in this order
The order below is arranged as "stop the loss first, deal with the aftermath later." If you can still log in, work down from step one; if you can't, jump straight to the next section.
1) Change your login password immediately
Your first cut takes out the key the attacker most likely holds — the login password. Change it to a strong password that's brand new and never used anywhere else. The point of this step: if they got in via credential stuffing or a leaked password, changing it shuts that door on any entry point outside the current session. Note that changing the password on its own may not immediately kick out sessions the attacker is already logged into, which is why the next step follows right on.
2) Emergency-freeze the account
Binance has an emergency freeze / disable account entry point for quickly suspending sensitive actions (login, trading and withdrawals get restricted) when you suspect a breach. This is the single most important move of the first ten minutes — it blocks the "keep moving coins out" path before you've even started going through things item by item. Once frozen, the account goes into a restricted state, and you follow the official prompts to verify and unfreeze later. The exact name and location follow whatever Binance's official page currently shows, and you really should know where it lives ahead of time (which is exactly why we keep saying: learn the doors first).
3) Revoke every API key
If you've ever created API keys for copy-trading, quant, or bookkeeping tools, this is the most overlooked and most dangerous back door when you get hacked. The attacker may not have logged into your account at all — instead they got hold of an over-privileged API key that lets a program place orders and withdraw on your behalf. So go into API management and delete every key, no exceptions — don't sit there sorting out which one is the problem; in a compromised state, wiping them all is safest, and you can rebuild what you need once things are secure. More in API key security and permissions.
4) Check and boot unfamiliar login devices
Go into device management / login activity and look over which devices and sessions are currently online. Remove or log out every device and session that isn't you. This closes the "window they've already climbed through" — changing the password alone sometimes leaves their live session intact. While you're at it, note the time, IP and device details of the unfamiliar logins, and screenshot them as evidence. Where to look and how to kick them, see device management and unusual logins.
5) Go through your other security settings for tampering
Once inside, attackers often quietly rewire your security settings to hold onto control long-term: swapping out your bound 2FA, changing your anti-phishing code, adding their own withdrawal address to the whitelist, changing your email or phone number. Check each one —
- 2FA: is it still your own authenticator? If it's been swapped, re-bind it.
- Withdrawal whitelist: has an unfamiliar address appeared? Delete it. (This is also why having a whitelist on in the first place matters — see how to set up a withdrawal whitelist.)
- Bound email / phone number: if these were changed, it means they're going for a long-term takeover — change them back at once and file an official appeal.
- Anti-phishing code: check it's still the string you set.
6) Contact official Binance support and file a ticket
Once the bleeding's stopped, file a ticket through the support entry point inside the official app or website, explaining the account was compromised and listing the anomalies you saw (unusual login times, the transaction ID / TxID of any odd withdrawal, settings that were altered). Hand over the screenshots and notes you took earlier. If there was an unauthorised withdrawal, providing the TxID matters — on the off chance the assets are still parked at some stage inside the platform, support may be able to help intercept them. Do this through official channels only, and don't trust any "support agent" who reaches out to you.
If you're already locked out
Password changed, 2FA swapped, email tampered with — you've been booted out of your own account. At this point the only proper path is Binance's official account-recovery / appeal flow:
- In the official app or official website, find the "can't log in / account recovery / appeal" entry point and submit identity-verification materials as prompted. Have ready the email and phone number you registered with, your identity details, and anything that proves the account is yours (deposit history, KYC information, and so on).
- Recovery usually needs manual review, so it'll be slow and they'll ask for materials more than once — that's normal. Cooperate patiently, and don't go chasing some third party promising to "speed up recovery" just because you're in a hurry.
- Whatever you do, don't click into a so-called "Binance support hotline" or "official recovery centre" from search results, and ignore any "staff member" who adds you on Telegram or WeChat. These are almost all second-round scams cashing in on your misfortune.
Can you get it back? Straight answer
This is what everyone cares about most — and what scammers exploit most. Let me lay out the reality so you can make your own call:
If the coins are still inside Binance (not yet withdrawn, or the withdrawal is still in processing / risk-control), there's some chance. If you froze fast and reported early, support may be able to hold it inside the platform. That's the entire point of racing the clock in those first ten minutes.
If the coins have already been withdrawn to an external on-chain address, realistically, they're mostly gone. The reasons are hard and unforgiving:
- On-chain transfers are irreversible. Once a transaction is confirmed on the blockchain, there's no "undo" button, and no support agent who can roll it back. That's by design, not a Binance oversight.
- The attacker moves and obfuscates it instantly. Professional coin thieves route it through several addresses and mixing services fast; you can watch the flow on-chain, but watching it isn't the same as getting it back.
- Cross-platform, cross-border. The coins may flow to another exchange or even overseas — the chain of cooperation gets long and the success rate low.
So the honest conclusion is: do the stop-the-bleeding, the appeal and the police report, because doing them is what gives you that "maybe" — but don't pin your hopes on the word "recover." Anyone or any outfit telling you "pay a service fee and we'll get your coins back for you" is almost certainly a scammer — the second harvest reaped off victims.
Does reporting to police help
Report it, but manage your expectations.
The real value of reporting is leaving a formal case record and a receipt. That receipt carries weight later when you're pursuing a platform appeal, a possible insurance claim, or a legal process; and when the amount is large or organised fraud is involved, the police may open a case and coordinate on the investigation.
But be clear about the limits too: crypto is cross-border, anonymous and irreversible, so the share the police can actually recover isn't high, and the process is slow. Think of reporting as "putting this on the official record and keeping future options open," not "report it and get the money back."
When you file, bring as much as you can: the TxID of the unauthorised transaction, the attacker's address, the timeline, your ticket history with official Binance support, and your own account details. The fuller the file, the easier it is to open a case.
"The police" is the wrong address in most of the English-speaking world
In England, Wales and Northern Ireland, fraud doesn't go to your local force at all — it goes to Action Fraud, the national reporting centre, on 0300 123 2040 or through its online tool. Scotland is the exception and goes to Police Scotland directly. Canada has the Canadian Anti-Fraud Centre; investment fraud should also go to your provincial or territorial securities regulator. Australia has ReportCyber, which replaced the older ACORN system, with ASIC as the second address for crypto-asset misconduct.
Walking into a local station and asking them to take a crypto report will usually get you sent to one of those anyway, a day later — and a day matters. Which desk takes your report, country by country, what to have ready before you start the form, and why the American one everybody links to is no use to you.
Watch for the second scam: fake "recovery" support
This gets its own section because it cuts so deep. A victim is panicking and grasping at any hope, and scammers zero in on exactly that state of mind:
- Someone reaches out in the comments, in a group, or by DM, posing as the "Binance official security team" or an "on-chain tracing expert," claiming they can help you recover — as long as you pay a service fee or deposit up front.
- A "support agent" asks you for your seed phrase, private key or verification code, saying they need to "verify your identity" or "help move your remaining assets." Anyone asking for your private key, seed phrase, password or verification code is a scammer, without exception.
- The "Binance human support hotline" ranking at the top of search results — the voice on the other end will walk you step by step into losing the rest of your money too.
Remember one iron rule: official Binance will never DM you first, never ask for your password / verification code / seed phrase, and never make you pay before "recovering" anything. Every legitimate action happens inside the official app or website you log into yourself. Being hacked is bad enough — don't let yourself get cut a second time.
Once the dust settles: review and harden
You've got control back and saved the remaining assets — don't rush to close the book. Spend some time working out how they actually got in, or you'll patch up and still leak again:
- Was it the password? Had you used this password elsewhere, so a leak-and-stuff attack got in? Change every reused password across all your accounts right now, and let a password manager generate a unique one per site. You can run the new one through the password strength checker to see if it's tough enough.
- Was your 2FA too weak? If you'd only been using SMS codes, it was probably a SIM swap or intercepted code. Upgrade your 2FA to an authenticator app or a security key — for why SMS is the weakest, see SMS 2FA and SIM swapping.
- Were you phished? Cast your mind back — did you click a suspicious link recently, or type your password into some "Binance" page? If so, set an anti-phishing code and build the habit of checking the sender domain.
- Was a device infected? Scan the computer and phone you use regularly; if anything's suspect, reinstall the OS or log in from a different device, and change every related password.
- Was an API key leaked? Did a key you handed some tool have too much permission and then get exposed? From now on, grant minimum permissions and bind an IP whitelist.
Find the root cause, fix the right thing, and getting hacked won't have been for nothing. The full settings list is in the complete account security checklist, or just run the account security check-up, tick a few boxes, get a score for your account as it stands, and see which defences are still missing.
How to not go through this again
Hardening after the fact and prevention before it are really the same checklist. Set these all up in one go and you block the vast majority of the ways accounts get taken:
- Use an authenticator app or security key for 2FA, with SMS as backup only — this one blocks the most attacks.
- Turn on a withdrawal address whitelist and add your usual addresses ahead of time. This is the fallback insurance that means "even if they log into your account, they can't move the coins."
- Keep your login password unique and unreused, paired with a password manager.
- Set an anti-phishing code, and build the habit of "any 'Binance' email without the code is fake."
- Grant API keys minimum permissions only, and delete unused ones promptly.
- Know where the emergency freeze and hacked-account appeal entry points are — when it really happens, those ten seconds are worth a lot.
Treat this as something to finish on the day you register, not a fix after things go wrong. One full guide covers every layer in depth: the defences you should turn on from day one.
FAQ
My Binance account was hacked and the coins were moved out. Can I get them back?
Honestly, in most cases no. An on-chain transfer is irreversible once confirmed, so the main thing Binance can do is freeze whatever's still inside the platform and cooperate with the investigation. Once coins have left for an external address and been obfuscated, there's almost no realistic way to claw them back. Do the right things anyway — file an official appeal, keep evidence, report to police if warranted — but don't pin your hopes on recovery.
What's the very first thing to do when I notice the hack?
If you can still log in: change your login password right away, then use emergency freeze to pause the account, revoke every API key, and boot any unfamiliar login devices. If you're already locked out (the password was changed), go straight to Binance's official account-recovery/appeal flow — don't mess around on a spoofed page or with so-called support. The core of the order is stop the bleeding first, appeal second.
Is it worth reporting stolen crypto to the police?
Worth doing, but manage your expectations. A report leaves a formal record, and in some cases police can coordinate with the exchange or across borders; but the cross-border, anonymous, irreversible nature of crypto keeps the real recovery rate low. The case receipt is useful material later for a platform appeal or legal process, so filing is still advised.
Someone says they can recover my coins for a service fee — can I trust them?
Almost always a scammer. This is a second-round scam that targets victims specifically. Ignore anyone who says "pay first, recover later" or asks for your seed phrase / private key / verification code to "verify your identity." Official Binance won't DM you first, and every legitimate action happens inside the official app or website you log into yourself.
What if I can't find these entry points?
Binance's interface and feature names change from time to time. This article is about the order of actions and what each step does; the exact entry points follow whatever Binance's official page currently shows. If you can't find one, search the official help centre for terms like "emergency freeze," "account recovery," or "API management."
Sources
- Binance official help centre · entries on account security and handling theft (binance.com/en/support, refer to the current official page)
- Binance security page · account protection and emergency-freeze notes (binance.com/en/security)