You typed your password into a phishing page. Here's the next hour, in order
Search this and you get the same list everywhere: change your password, run a scan, turn on 2FA, watch your accounts. None of it is wrong, but it skips the two things that actually decide how this ends — what exactly you handed over, and what order you do things in. Get the order wrong and the password you just changed can be changed back on you from another direction. This piece covers those two questions. It applies to any account that logs in with a password plus a code; exchange accounts just raise the stakes, because the assets sit right behind the login.
First, sort what you handed over
"I clicked a phishing link" covers everything from handing over an email address to handing over a password and a live code, and those are not the same event. Find your row below before you do anything else. Getting this right saves you a lot of pointless work, and stops you treating the genuinely bad tier as a minor scare.
| What you did on that page | Risk | Minimum response |
|---|---|---|
| Opened it, typed nothing | Low | Close it, don't return through that entry point; if you were pushed to download something, delete it and scan the device |
| Typed an email address or phone number | Low-mid | No password sweep needed, but expect targeted "support" calls and texts aimed at you next |
| Typed your login password | High | Work the order below, sign out of all sessions, and replace that password everywhere you reused it |
| Typed the password and an SMS or authenticator code | Highest | Assume they were inside; beyond passwords, audit whitelists, API keys and mailbox rules one by one |
| Signed or approved something in a wallet pop-up | Different track | That's an on-chain approval, not an exchange account breach, and it is handled differently — see below |
The first hour, in order
This sequence is for the "High" and "Highest" rows. The difference between it and the usual checklist is steps one and two — most write-ups say "change your password" without saying on which device or which account first.
- Move to a device that never touched the link. If the page pushed something onto your machine, the new password you type on it can be captured as you type it. Use another phone or another computer. If you genuinely have neither, clear out the suspect app, the extension you just installed and anything you just downloaded before you start.
- Change the email password first, the exchange password second. Order matters here: your mailbox is the root of nearly every account recovery. Change only the exchange password while the mailbox is still theirs, and they simply run a forgotten-password flow and change it straight back. While you're in there, turn on 2FA for the mailbox.
- Change the exchange password to something never used anywhere else. If the new password is an old password from another site, you've fitted a lock that opens with a key already in circulation — see how credential stuffing opens accounts one by one.
- Sign out of all devices, deliberately. A password change does not reliably terminate live sessions. On most platforms this is a separate button in the security settings and you have to press it.
- Replace that password on every other site that shared it. When someone gets a working pair, the first thing they usually do isn't to log into your exchange — it's to try it everywhere else.
- Only then audit for anything planted (section four), and write down what happened: when you opened it, what you typed, the sender address and the raw link. Don't delete the email or text — screenshot it. If this ever goes to a support appeal, that record is the only evidence you'll have.
If you typed a code, assume they got in
Plenty of guides claim two-factor authentication blocks the overwhelming majority of phishing. That holds for a plain fake login page. It does not hold for a real-time relay page, which is the sort currently aimed at exchange accounts.
The mechanism is simple. The fake page doesn't store your details for later; it sits in the middle. You type into it, and it types into the real site at the same moment. The real site asks for a code, so it shows you that request. You enter the six digits, and it completes the login on the real site inside the code's 30-second window. Everything looks normal on your screen, and the login genuinely succeeds — just into a session on their side.
So the test is blunt: if you entered an SMS or authenticator code on a suspicious page, treat it as though a valid session was handed over, and work the top tier. "But I had 2FA on" is not grounds for downgrading.
One thing worth stating plainly: only one class of second factor actually resists relay phishing, and that's hardware security keys and passkeys. They check the domain they're signing for, so on a lookalike domain nothing usable comes out and there's nothing to relay. How they work and how to bind them is in security keys and passkeys.
Four places a way back in gets left
If someone did get in, the part that lulls people is this: they often don't touch your assets straight away. A large withdrawal trips risk controls and sends you an email. Leaving a quiet way back in and returning later costs them far less. So after the passwords, go through these:
- New addresses in the withdrawal whitelist. The classic move: add their address, wait out the activation delay, come back. The whitelist is a good feature used against you — see how the withdrawal whitelist works.
- API keys you didn't create. A key with trading or withdrawal permissions bypasses the logged-in state you see in the browser entirely. Revoke anything unfamiliar — see API key security and least privilege.
- Unknown entries in devices and sessions. Device names you don't recognise, cities and times that don't line up. See device management and suspicious logins.
- A changed anti-phishing code. If the shared phrase between you and the platform has been swapped, the next fake email can carry the "right" phrase and sail past you. See what an anti-phishing code is.
- Swapped phone number, email or verification methods. Miss this one and every recovery route now belongs to someone else.
Rather than working from memory, run the account security checkup over the settings. If you can already see actions you did not take, stop reading this page and follow the first ten minutes of a hacked account, or step through the incident decision tree.
The mailbox step everyone skips
Almost every checklist says "change your email password". Very few tell you to look at the mailbox rules. Once someone has been inside your mailbox, changing the password would alert you; leaving a rule behind would not:
- Auto-forwarding — a copy of everything arriving goes to their address, invisibly to you.
- Filters — anything containing "withdrawal", "login" or "security" gets archived or binned on arrival, so the platform's alerts never reach you.
- Recovery email and recovery phone — swapped to theirs, that's a long-term key cut for them.
- App passwords and third-party authorisations — these can survive a master password change.
Providers name these screens differently, but they live roughly under "Settings → Forwarding", "Filters and blocked addresses" and "Security → apps and devices with access". Once the mailbox password is changed, walk all four. It's the highest-value ten minutes in the whole cleanup.
Three things not to do
- Don't change passwords on the suspect device. Until it's been cleaned, every new password you type there may be wasted effort.
- Don't take the "support" call. What you just typed on the fake page is exactly the raw material for a follow-up scam: they can quote your email and what you just did, which makes them sound official. How to test a message is in telling a real platform message from a fake one, and the phishing check walks the same points. Hold on to the direction of travel: support does not ring you to talk you through your own account.
- Don't hire a "fund recovery" service. Accounts promising to get your money back are, overwhelmingly, after a second payment.
Reporting is worth doing separately, and where you report depends on where you live rather than on where the exchange is registered. If you're outside the United States and unsure who receives this kind of report, we set out the routes in reporting a hacked crypto account outside the US.
What to fix over the next week
Once the emergency is handled, close the hole, or the same week repeats itself:
- Move your second factor up a grade — off SMS onto an authenticator, and onto a hardware key or passkey if you can. Trade-offs in the complete 2FA guide.
- Turn on the withdrawal whitelist — its value is precisely this scenario: even from inside the account, coins can only go to addresses you approved in advance.
- Make every password unique — generated and stored by a password manager, so you never have to remember them. It's the cheapest way to stop one leak becoming five.
- Set an anti-phishing code and switch on login and withdrawal alerts — the first makes unbadged "official" mail obvious, the second puts unusual activity on your phone instead of waiting for you to look.
FAQ
I only opened the link and typed nothing. Do I need to change passwords?
Not for that alone. Loading a page does not hand over your password. Three things are worth doing: close the page, do not go back in through that entry point, and if you were prompted to download or install anything, delete it and run a scan on the device. The step change in urgency comes from what you typed, not from the click.
I typed my password but no verification code. Am I still safe?
Treat the password as leaked, but the account most likely has not been entered, because the second key is missing. For this tier: move to a device that never touched the link, change your email password first, then the exchange password, then sign out of all sessions, and replace that password anywhere else you used it. After that, check the device list and the withdrawal whitelist for anything new.
I already changed the password. Why sign out of every device as well?
Because a password change does not always kill sessions that are already established. If someone got in before you changed it, their side may still hold a live session and keep working. Signing out everywhere is usually a separate button in the security settings, and pressing it is what cuts that older path. Generic checklists routinely skip this step.
I entered a six-digit code on the fake page. Do I need to re-bind my authenticator?
The six-digit code lasts about 30 seconds and is single use, so it is already worthless and no re-binding is needed for it. What does need re-binding is the other thing: the long setup key shown when you first bind an authenticator, or the QR code behind it. That is the seed that keeps generating codes. If you typed, screenshotted or pasted the setup key on a suspicious page, treat the seed as exposed and re-bind.
Should my first move be to send all my assets somewhere else?
Moving assets is a poor first move. The goal of the first hour is to regain control: clean device, new passwords, sessions closed, planted whitelists and API keys removed. Acting before you hold control can just push funds toward an address someone else prepared. If you can already see logins, transfers or withdrawals you did not start, this article is no longer the right one — switch to the hacked-account sequence.
Sources
- Binance Help Center · account security, suspicious logins and two-factor entries (binance.com/en/support, go by the current official page; checked 2026-08-30)
- Binance · how to reset 2FA when you cannot access the account (official guide, checked in a real browser 2026-08-30)
- RFC 6238 · TOTP time step and single-use properties of the rotating code (RFC 6238)