Zhenku
Ward · Test the message

How to tell you've got the real Binance app, not a phishing fake

Zhenku editorial · Cheng Mo Updated 2026-07 About 13 min
Cover: how to tell you've got the real Binance app

The most insidious thing about a fake app is that, once installed, it looks almost exactly like the real one — same icon, same interface, and it lets you "log in" just the same. The only difference is that the login, password and codes you type in are all passed straight to someone else. By the time you notice something's off, the money may already have moved. So installing the Binance app is a step worth two extra minutes of careful checking. This piece lays out "how to install it right, how to verify once installed, and how to recover if you installed a fake" in one go, and throughout it publishes no address on Binance's behalf and doesn't push you to download anything — you're safer holding the key to verification in your own hands.

What a fake app or phishing site actually does to you

Get the harm straight first, and you'll be willing to put more care into this step. A fake Binance app or a phishing site is, at bottom, a shell that looks official, built to trick you into handing over sensitive information. They tend to do a few things:

Of these traps, the deadliest are the code and seed-phrase ones, because they let whoever's behind it log straight into the real account or sweep away on-chain assets outright. And it's precisely because the harm is this direct that "install the right app, reach the right site" sits near the front of account security.

One principleA genuine official app will never ask you for a seed phrase, nor have some "support agent" act on your behalf outside the app. Any step that asks you to hand over a seed phrase, or read a code out to a person, is where you stop.

The right way: search your app store for the official developer

The steadiest path to installing the Binance app is to open your phone's built-in app store and search and install it yourself — rather than tapping a link someone sent or scanning a code someone gave you. An app store has a review process, and while it can't guarantee zero fakes, it's far safer than a channel of unknown origin.

The key isn't "being able to find it" but "recognising which one is official once you've found it." A fake can sit in the results with a very similar name and a very similar icon, so name and icon alone aren't enough — you must go on to check the developer information (next section).

Don't skip thisDon't search a search engine for "Binance download" and then tap a top result — paid promotions and fakes often dominate the top spots, and tapping through is very likely a phishing page. To reach the official site, type the address yourself or use a bookmark you saved earlier; to install the app, go through your app store. Both routes depend on no link anyone hands you, and that's exactly why they're reliable.

Check: developer name, reviews, download count

On the app store's download page, don't rush to tap install — look at these few items first. Taken together, they help you tell an official app from a fake:

Developer name

This is the most important item. The download page usually shows the name of the developer/publisher, and a fake finds it hard to fully forge the official entity. Check whether that name is Binance's official publishing entity, with the exact name deferring to official announcements and what the app store shows. If the developer reads as an individual's name, an unfamiliar company, or a string of gibberish characters, you can basically call it a fake. Tapping the developer name also shows the other apps under it: an official entity usually has a tidy set of related apps, while a faker often has a mess, or nothing but this one "name-borrowing" thing.

Number and content of reviews

An official app usually has a huge number of reviews, on a large order of magnitude; a fake often has very few, or a batch of near-identical positive reviews piled up over a short period. Read a few recent reviews — if a user is shouting "this is fake" or "got hacked after logging in" in the comments, that's a strong danger sign.

A few "abnormal shapes" in the review section are especially worth watching: a batch of very short, near-identically worded five-star reviews appearing over a short window (padding); positive reviews that are all vague — "works well," "not bad" — with nobody mentioning any specific feature; or a sharp split between good and bad, where genuine, carefully written complaints of "got hacked" or "can't withdraw" sit among a pile of mechanical praise. Real users' reviews are mixed — praise and gripes, concrete situations; a wall of uniform praise is the abnormal thing.

History and download count

An official app generally has a fairly long listing history and a very high cumulative download/install count, with a continuous update record. A fake is often listed only recently, with a low download count and a very short update history. When these numbers don't match "what a top exchange should look like," be wary.

While you're at itTreat "developer name + review count + download count + how long it's been listed" as one group to look at together, not just one of them. A faker might forge one or two, but making all of these look real at once is hard. If any single one is clearly off, don't install it.

Download methods to steer clear of

The following ways of getting the app all carry clearly higher risk; avoid them where you can:

What they share: they all let someone else decide where you download from. Once you've handed over that initiative, verification is beside the point. Stick to "search your app store yourself, check the developer yourself," and this whole class of risk is largely sidestepped.

What to watch on iOS and on Android

Checking the developer and reading reviews applies to both systems, but because the mechanics differ, each has a few traps of its own.

On iOS

Installing apps on an iPhone is basically the one legitimate route through the App Store, which by itself blocks a large batch of fakes. What to watch for are the tricks that route around the store:

On Android

Android is open, with more sources to install from and more room for fakes, so take extra care:

One rule of thumbWhether on iOS or Android, any "Binance" that only works once you "trust a certificate, turn off a security setting, enable unknown sources, or install a profile" should be treated as fake first. A proper app takes the legitimate route through the system store and doesn't need you to lower your device's security bar for it.

After installing, how to double-check

Even after installing from the app store and checking the developer, don't fully let go. Around your first login, cross-check with a few internal signals — it's a double lock on "this is the real app."

Watch the domain and page behaviour after logging in

The web redirects and official links in the real app should land on a Binance official domain (the exact domain defers to official announcements). If a page inside the app sends you to an unfamiliar domain asking you to log in again, that's suspicious.

Use your anti-phishing code to verify in reverse

If you've set an anti-phishing code, then when an official email or in-app message is triggered after logging in, check whether it carries the code you set. An official message bearing the correct anti-phishing code is one piece of corroboration that "you really are dealing with the genuine account system." Note it only works for emails and in-app messages.

Set up two-factor and watch whether the flow is normal

Walk through the two-factor flow inside the app. The real app's 2FA is a standard flow tied into your account system; a fake app may give itself away at this step — for instance, its "verification" finishes without actually changing anything, or it lures you into entering extra sensitive information. If the flow is awkward or asks for more than makes sense, that's worth doubting.

Always hold this lineHowever legitimate the app looks, it should never ask you for a seed phrase, nor have you read a code out to any "person." The moment either of these red lines is crossed, stop — this is the tell a fake most often gives away.

How to confirm you're on the real site on desktop

Logging in through a browser on a computer has its own set of "confirm you're on the real site" habits, with the same logic as on the phone: don't get in by tapping search results — hold the entry point yourself.

Where you're most likely to trip up on desktop is "give it a quick search and tap the first one." Switch your way in from "search + tap" to "bookmark + type," and a phishing site struggles to fool you again. When you're unsure about a message or link, run it through the phishing message self-check to work through a few of the tests.

If you suspect you installed a fake, how to recover

If you've already installed a suspicious app, or entered information on a suspicious page, don't panic — work through this in order, the faster the better. The core idea is: switch to a clean device, route around the suspicious entry point, and change every security item you can.

  1. Uninstall the suspicious app: delete that app of unknown origin from your phone first, to stop it reading your information any further.
  2. Switch to a device you're sure is clean: use another phone or computer that's fine for the steps that follow, so you're not entering a password on a possibly compromised device.
  3. Reach the real site yourself: type the official address or get the real app from your app store — don't use the one you just uninstalled and don't tap any related link.
  4. Change passwords: change your login password and your fund password; if you've used this password elsewhere, change the related accounts too.
  5. Reset two-factor: register 2FA afresh so any old, possibly leaked verification pairing is invalidated.
  6. Check logged-in devices: look at logged-in devices in your security settings and kick out every unfamiliar one — a session already logged in won't drop automatically just because you changed your password, so clear it by hand.
  7. Revoke suspicious API keys: if you've ever connected any third-party tool or created an API key, go in and check for anything unfamiliar or over-permissioned, and delete and recreate anything suspicious. A fake app may have lured you into handing over API details, so don't miss this step.
  8. Check withdrawals and the whitelist: look for any unfamiliar withdrawal records or any unfamiliar address quietly added to the whitelist, and act at once if you find something off.
  9. If assets are already gone, treat it as a hack: if a transfer has already happened, the time window is critical — immediately follow hacked-account recovery step by step, freeze whatever can be frozen, and go through the appeal process with the official channel as fast as you can.
In a sentenceInstalling a fake app doesn't automatically mean you've been robbed — often, as long as you haven't yet entered sensitive information, or you change your password and 2FA promptly, you can keep the loss out. But that depends on catching it early and acting fast. This piece is only about account and asset security, is not investment advice of any kind, and provides no download address or "official site entry."

FAQ

Is downloading from a phone app store always safe?

An app store is far safer than a download link of unknown origin, but you can't be fully at ease. Fakes do occasionally slip into a store, so when downloading you should still check details like the developer name, the number of reviews and the historical download count — don't install just because the icon and name look right.

Someone sent me an APK installer — can I install it?

Not advisable. A third-party APK of unknown origin, an installer sent in a group chat or a direct message, or a download behind an unfamiliar QR code can all have been turned into a fake app that steals your login, password and codes once installed. To install the Binance app, search your phone's built-in app store for the official developer.

What if I suspect I installed a fake Binance app?

Uninstall the suspicious app first, then on a different device you're sure is clean, type the official address yourself or reach the real site through your app store, change your login and fund passwords, reset two-factor, check for and kick out unfamiliar logged-in devices, and check your withdrawal history for anything odd. If assets are already gone, follow the hacked-account flow as fast as you can.

How do I know what Binance's official developer name and domain actually are?

Defer to Binance's official announcements and what the app store currently shows — don't go on impressions or hearsay. The steadiest approach isn't to compare "does it look alike," but to search your app store and check the developer information, and to reach the site by typing the address yourself or using a bookmark you confirmed earlier, sidestepping every entry point anyone else provides.

CM
Cheng Mo · Zhenku editorial

"Cheng Mo" is a pen name and doesn't stand for any licensed expert. What we do is take Binance's official security rules and publicly known impersonation tactics and lay them out in an order an ordinary user can follow, checking the steps ourselves where we can. This is an independent, unofficial guide; it publishes no download address or official-site entry on Binance's behalf, and gives no investment advice. If you spot something we got wrong, do tell us via corrections.

Sources

  • Binance security page · notes on anti-impersonation and account security (binance.com/en/security, defer to the current official pages)
  • Binance official help centre · notes on anti-phishing and official channels (binance.com/en/support)