Zhenku
Guard · The Walkthrough Checklist

The Complete Binance Account Security Checklist: Every Guard to Switch On From Day One

Zhenku Editorial · Cheng Mo Updated 2026-07 About 15 min
Cover for the complete Binance account security checklist

Most people only go back and sort out their security settings after something's already gone wrong — someone logs into the account, the coins get moved out, or they click through a fake "Binance" email that looked completely real. The truth is, nearly all of that loss can be stopped by a handful of guards you set up in twenty minutes on the day you sign up. This is that list. For each guard we spell out what it protects against, how to switch it on, and the trap that's easy to fall into — you just work through it once.

First, get clear on who you're actually defending against

Before you change any settings, sort out where the threat comes from — that's the only way each guard downstream makes sense. When an exchange account gets taken over, it's almost always one of these routes:

The five guards below map one-to-one onto exactly these routes. They aren't independent switches — they stack, so if one gets bypassed, the next one still catches you. That's why we call them "the beast's five guards": an account that holds up never relies on a single lock, but on several doors in a row.

Guard one · Draw the line: passwords and the fund password

The first door is your password. It sounds like the most basic thing in the world, yet it's the one most people throw together without a second thought.

Login password: don't reuse it, don't make it short

The single most important point isn't "make the password complex" — it's that this password is used only on Binance and nowhere else. Credential-stuffing attacks feed on reuse: the email-and-password you used on some forum leaks, and the attacker tries the same pair against exchanges. Even a password that looks strong is a risk the moment it's been reused.

In practice: use a password manager to generate a long, random passphrase (a dozen-plus characters) just for Binance, so you don't have to remember it. If you'd rather not use a password manager, at the very least make sure this one password is different from every other account you have. Want a rough sense of how well your current password would hold up against a brute-force attempt? Try our password strength checker (estimated locally, nothing uploaded).

Fund password: don't make it the same as your login password

Binance has a separate fund password (withdrawal password), distinct from your login password, used for sensitive actions like withdrawals. The whole point of it is this: even if someone gets your login password and logs in, without the fund password they can't touch your money. So these two passwords must be set to different values — make them the same and you've set it for nothing. For how to set it and how to reset it if you forget, see the fund password piece.

While you're at itRemember that Binance has an "emergency freeze" option: if you ever suspect something's wrong, you can freeze the account fast and pause sensitive actions, which buys you time to sort things out. Know where it lives now, so you're not scrambling when it actually matters.

Guard two · Set the eyes: two-factor authentication (2FA)

Two-factor authentication (2FA) gives you the most protection for the least effort of all five guards: with it on, a password alone won't get anyone into your account. But "2FA is on" and "2FA is set up properly" are two different things.

Binance supports several 2FA methods, and they're a long way apart on security:

Our advice: get an authenticator app on at the very least, and demote SMS from "the only method" to a backup. If you can, add a security key or passkey on top. For how to choose between the methods and how to set each one up, the complete 2FA guide goes into more detail, or you can use the 2FA methods comparison table to see the differences at a glance.

Don't skip thisWhen you set up an authenticator, Binance gives you a string of backup keys (recovery codes). Write them down offline and keep them somewhere safe. Change or lose your phone and, without them, you can lock yourself out. For the full move-to-a-new-phone process, see migrating 2FA to a new phone.

Guard three · Verify the message: the anti-phishing code

The first two guards stop "someone logging into your account." The third stops "you being tricked into opening the door yourself." The anti-phishing code is a private passphrase agreed between you and Binance: once you set it, every legitimate email and in-account message Binance sends you carries this code that you chose.

That makes telling real from fake dead simple: an email claiming to be from Binance with no anti-phishing code in it is almost certainly fake, so don't touch the links inside. This guard costs next to nothing (two minutes to set) yet blocks a large chunk of phishing emails. For how to set it and how to make it hard to guess, see the anti-phishing code piece.

One thing to note: the anti-phishing code only covers the emails and in-account messages Binance sends you. It won't appear in a text, a third-party messaging app, or a phone call. So if you get a call from "Binance support" or an "official" DM on Telegram, remember that Binance won't message you out of the blue and will never ask for your password or verification code. If you're unsure whether a message is genuine, run it past a few checks with our phishing message checker, or read how to confirm whether a "Binance" message is real.

Guard four · Bolt the door: withdrawal whitelist and API

The earlier guards are about "don't let anyone in." This one is about "even if they get in, they can't carry anything out" — the last guard, and the most important safety net against actual loss.

Withdrawal address whitelist

With the withdrawal address whitelist switched on, your account can only send coins to addresses you've added to the list in advance; unfamiliar addresses simply can't receive a withdrawal. That means even if someone logs in and gets past your password and 2FA, they still can't move the coins to an address of their own. For anyone holding long term, this one is close to non-negotiable.

The trade-off is that a newly added address usually takes a waiting period before it goes live (a cooling-off delay Binance put in deliberately, precisely to stop "add an address and drain it the moment the account is breached"). So add your regular withdrawal addresses ahead of time. For where the switch is and how long it takes to take effect, see how to turn on the withdrawal whitelist; for fuller withdrawal safety (checking addresses, small test sends, choosing the network), see the complete withdrawal security guide.

API permissions: grant as little as you can get away with

If you've ever used a copy-trading, quant, or portfolio-tracking tool, you've probably created an API key at some point. An API hands part of your account's controls over to a program, and the risk is granting too much and then leaking it. Three rules:

For the longer version, see API key security and permissions, or use the API permission risk checker to tick through whether the permissions you've handed out are over the top.

Guard five · Repel the attacker: if you do get hacked

With the first four guards fully in place, the odds of being hacked are already very low. But there's no "absolute" in security, so the fifth guard is your plan: what to do in the first ten minutes if it actually happens. The rough order is — change your login password immediately, use emergency freeze to pause the account, revoke every API key, check for and boot off unfamiliar login devices, and contact Binance officially to start an appeal. Get the order wrong or move too slowly and you can miss the window to stop the coins leaving.

There's a lot of detail here, so we've written it up separately in the complete hacked-account recovery guide, and built a hacked-account response decision tree — when you're genuinely panicking, you just follow the steps one tap at a time. Read it now while you're calm so you know the drill, rather than opening it for the first time mid-crisis.

A checklist you can tick off

Here are the five guards boiled down into a list you can tick item by item — work through it once:

  1. Your Binance login password is not used anywhere else, and it's long enough.
  2. You've set a fund password, and it's different from your login password.
  3. Your 2FA runs on an authenticator app or a security key, with SMS kept only as a backup.
  4. The authenticator's backup recovery codes are written down offline and stored safely.
  5. You've set an anti-phishing code, and you remember it only ever appears in emails and in-account messages.
  6. The withdrawal address whitelist is on, with your regular addresses already added.
  7. You've reviewed your API keys: minimum permissions, and anything suspicious deleted.
  8. You've had a look through your login devices and booted off any you don't recognise.
  9. You know where emergency freeze and hacked-account recovery live.

Too much of a chore to check them off one at a time? Use the account security check-up — answer a few questions and it gives you a security score, lists which guards you're still missing, and how to fix each one.

A few common misconceptions

We worked through the whole set of settings from scratch, following the official pages, and jotted down the spots people most often take for granted:

In a lineSecurity settings can't remove market risk — they stop "someone taking your coins," not "the market falling." Those are two different things; don't mix them up. This piece is only about account and asset security, and it isn't investment advice.

Common questions

Which setting should I switch on first?

If you only have time for one thing, move your 2FA onto an authenticator app or a security key and stop relying on SMS alone; after that, the anti-phishing code and the withdrawal whitelist. Those three block the overwhelming majority of attacks.

If I switch all this on, is my account guaranteed not to be hacked?

No — nothing is absolutely safe. These settings drive the odds and the losses right down, but social engineering, a compromised device, or leaking your own password can still go wrong. Security is layers of defence stacked up, not a one-time fix.

Is the withdrawal whitelist a hassle to have on?

A little: adding a new address usually takes a waiting period before it goes live. But what you get in return is "even if someone logs into my account, they can't move the coins" — well worth it for anyone holding long term. Add your regular addresses ahead of time and it's no bother.

Will the exact location of these settings change?

Yes. Binance tweaks its interface and feature names now and then. This piece explains what each setting does and the trade-offs, but the exact location is whatever Binance's own pages currently show; if you can't find something, search the relevant keyword in the official Help Center.

CM
Cheng Mo · Zhenku Editorial

"Cheng Mo" is a pen name, not a stand-in for any licensed expert. What we do is take Binance's official security settings and published rules and lay them out in an order an ordinary user can follow, walking through the steps ourselves to check them wherever we can. We don't give investment advice; if you spot something we've got wrong, please tell us via corrections.

Sources