How to tell you've got the real Binance app, not a phishing fake
The most insidious thing about a fake app is that, once installed, it looks almost exactly like the real one — same icon, same interface, and it lets you "log in" just the same. The only difference is that the login, password and codes you type in are all passed straight to someone else. By the time you notice something's off, the money may already have moved. So installing the Binance app is a step worth two extra minutes of careful checking. This piece lays out "how to install it right, how to verify once installed, and how to recover if you installed a fake" in one go, and throughout it publishes no address on Binance's behalf and doesn't push you to download anything — you're safer holding the key to verification in your own hands.
- What a fake app or phishing site actually does to you
- The right way: search your app store for the official developer
- Check: developer name, reviews, download count
- Download methods to steer clear of
- What to watch on iOS and on Android
- After installing, how to double-check
- How to confirm you're on the real site on desktop
- If you suspect you installed a fake, how to recover
- FAQ
What a fake app or phishing site actually does to you
Get the harm straight first, and you'll be willing to put more care into this step. A fake Binance app or a phishing site is, at bottom, a shell that looks official, built to trick you into handing over sensitive information. They tend to do a few things:
- Steal login and password: the email/phone number and password you enter on a fake login page go straight into their database.
- Steal codes: it pretends "verification is needed" and gets you to enter a two-factor or SMS code, then, while the code is still valid, whoever's behind it immediately uses it to log into your real account.
- Push you to transfer: some fake apps show a fake balance and a fake "support message," tricking you into sending coins to an address to "activate/unfreeze."
- Fish for your seed phrase: if it poses as a version with a wallet, it may lure you into importing or "backing up" a seed phrase — and once a seed phrase leaks, on-chain assets are all but unrecoverable.
- Sit and harvest information: a fake app on your phone may keep reading your clipboard, notifications and text messages, siphoning them off over time.
Of these traps, the deadliest are the code and seed-phrase ones, because they let whoever's behind it log straight into the real account or sweep away on-chain assets outright. And it's precisely because the harm is this direct that "install the right app, reach the right site" sits near the front of account security.
The right way: search your app store for the official developer
The steadiest path to installing the Binance app is to open your phone's built-in app store and search and install it yourself — rather than tapping a link someone sent or scanning a code someone gave you. An app store has a review process, and while it can't guarantee zero fakes, it's far safer than a channel of unknown origin.
- iPhone: open the built-in App Store, type "Binance" into the search, and find the official one among the results.
- Android: open the trusted app store that came with your device (it differs by brand), search the same way, and pick the official one from the results.
The key isn't "being able to find it" but "recognising which one is official once you've found it." A fake can sit in the results with a very similar name and a very similar icon, so name and icon alone aren't enough — you must go on to check the developer information (next section).
Check: developer name, reviews, download count
On the app store's download page, don't rush to tap install — look at these few items first. Taken together, they help you tell an official app from a fake:
Developer name
This is the most important item. The download page usually shows the name of the developer/publisher, and a fake finds it hard to fully forge the official entity. Check whether that name is Binance's official publishing entity, with the exact name deferring to official announcements and what the app store shows. If the developer reads as an individual's name, an unfamiliar company, or a string of gibberish characters, you can basically call it a fake. Tapping the developer name also shows the other apps under it: an official entity usually has a tidy set of related apps, while a faker often has a mess, or nothing but this one "name-borrowing" thing.
Number and content of reviews
An official app usually has a huge number of reviews, on a large order of magnitude; a fake often has very few, or a batch of near-identical positive reviews piled up over a short period. Read a few recent reviews — if a user is shouting "this is fake" or "got hacked after logging in" in the comments, that's a strong danger sign.
A few "abnormal shapes" in the review section are especially worth watching: a batch of very short, near-identically worded five-star reviews appearing over a short window (padding); positive reviews that are all vague — "works well," "not bad" — with nobody mentioning any specific feature; or a sharp split between good and bad, where genuine, carefully written complaints of "got hacked" or "can't withdraw" sit among a pile of mechanical praise. Real users' reviews are mixed — praise and gripes, concrete situations; a wall of uniform praise is the abnormal thing.
History and download count
An official app generally has a fairly long listing history and a very high cumulative download/install count, with a continuous update record. A fake is often listed only recently, with a low download count and a very short update history. When these numbers don't match "what a top exchange should look like," be wary.
Download methods to steer clear of
The following ways of getting the app all carry clearly higher risk; avoid them where you can:
- An APK sent in a group chat or a direct message: an installer of unknown origin may have data-stealing code planted in it, and installing it is as good as handing over your account.
- Downloading via an unfamiliar QR code: a QR code on a poster, in a direct message or in a comments section — you have no idea where it points, and it's very likely a phishing download page.
- Third-party "app markets" / cracked-software sites: download sites that aren't built into your system and are of unknown provenance are a perennial breeding ground for fakes.
- A download link pushed by "support": anyone claiming to be support and telling you to tap a link to install a "dedicated" or "secure" version is almost always a fake. The real thing doesn't work this way.
- A download button in an email or text: "security upgrade" or "update now" paired with a download link should be treated as fake first. For how to verify messages like this, see how to tell whether a "Binance" message is real.
What they share: they all let someone else decide where you download from. Once you've handed over that initiative, verification is beside the point. Stick to "search your app store yourself, check the developer yourself," and this whole class of risk is largely sidestepped.
What to watch on iOS and on Android
Checking the developer and reading reviews applies to both systems, but because the mechanics differ, each has a few traps of its own.
On iOS
Installing apps on an iPhone is basically the one legitimate route through the App Store, which by itself blocks a large batch of fakes. What to watch for are the tricks that route around the store:
- An unfamiliar TestFlight invite: TestFlight is Apple's beta-distribution channel, and some people use it to push a "beta" or "exclusive" Binance to trick you into installing. Don't tap a TestFlight link of unknown origin — an ordinary user has no need to use an exchange through a beta.
- An enterprise certificate / configuration profile: if installing some "Binance" asks you to go into "Settings - General - VPN & Device Management" and trust an enterprise certificate or profile, stop right there. A proper App Store app doesn't need you to trust a certificate by hand, and that step is close to handing over the front-door key.
- "You have to change a system setting to use it": any "Binance" that only runs once you turn off some security setting or install a profile should be treated as fake.
On Android
Android is open, with more sources to install from and more room for fakes, so take extra care:
- "Allow install from unknown sources" is a high-risk switch: when installing an APK of unknown origin, the system asks you to enable this permission. Once it's on, you've opened the door to sideloaded fakes. Turn it off once you're done and don't leave it on as a matter of course.
- Stick to the trusted app store that came with your device: the built-in store differs by phone brand, so use your device's original one; don't install from an unfamiliar "third-party app market."
- Watch for outlandish permission requests: an exchange app that, out of the gate, wants to read your texts, read your contacts, or use accessibility services (which can simulate taps and read the screen) is highly suspicious — those are exactly the permissions used to steal codes and information.
After installing, how to double-check
Even after installing from the app store and checking the developer, don't fully let go. Around your first login, cross-check with a few internal signals — it's a double lock on "this is the real app."
Watch the domain and page behaviour after logging in
The web redirects and official links in the real app should land on a Binance official domain (the exact domain defers to official announcements). If a page inside the app sends you to an unfamiliar domain asking you to log in again, that's suspicious.
Use your anti-phishing code to verify in reverse
If you've set an anti-phishing code, then when an official email or in-app message is triggered after logging in, check whether it carries the code you set. An official message bearing the correct anti-phishing code is one piece of corroboration that "you really are dealing with the genuine account system." Note it only works for emails and in-app messages.
Set up two-factor and watch whether the flow is normal
Walk through the two-factor flow inside the app. The real app's 2FA is a standard flow tied into your account system; a fake app may give itself away at this step — for instance, its "verification" finishes without actually changing anything, or it lures you into entering extra sensitive information. If the flow is awkward or asks for more than makes sense, that's worth doubting.
How to confirm you're on the real site on desktop
Logging in through a browser on a computer has its own set of "confirm you're on the real site" habits, with the same logic as on the phone: don't get in by tapping search results — hold the entry point yourself.
- Type the address yourself or use a bookmark: the first time you reach the official site and confirm it's correct, save it as a bookmark and always go in through the bookmark from then on. Don't search a search engine and tap a top result, where fakes and ads are often mixed in.
- Check the domain in the address bar: before logging in, glance at the address bar to see whether the domain is the official one (deferring to official announcements). Read the main domain right to left — watch for tricks like an extra letter, a swapped suffix, or "binance" stuffed into a long subdomain (something like binance.xxxx.com, where the real main domain is xxxx.com, not Binance).
- Don't tap the ad slots at the top of the results: the very top of a search page often has promoted slots labelled "ad/sponsored," and fakes love buying these to pose as official and sit first. Reach the site by bookmark or by typing, don't take the easy road and tap that most eye-catching ad.
- Mind the browser's security warnings and certificate: on a page with no padlock in the address bar, or one warning of a certificate problem or "not secure," don't enter any account details. The padlock only means this connection is encrypted, not that the site is official — so look at the padlock, look harder at the domain, and check both together.
- Don't install browser extensions of unknown origin: some malicious extensions tamper with the page or steal your input. For installing anything Binance-related, come back to the principle of "official channel, confirm it yourself."
Where you're most likely to trip up on desktop is "give it a quick search and tap the first one." Switch your way in from "search + tap" to "bookmark + type," and a phishing site struggles to fool you again. When you're unsure about a message or link, run it through the phishing message self-check to work through a few of the tests.
If you suspect you installed a fake, how to recover
If you've already installed a suspicious app, or entered information on a suspicious page, don't panic — work through this in order, the faster the better. The core idea is: switch to a clean device, route around the suspicious entry point, and change every security item you can.
- Uninstall the suspicious app: delete that app of unknown origin from your phone first, to stop it reading your information any further.
- Switch to a device you're sure is clean: use another phone or computer that's fine for the steps that follow, so you're not entering a password on a possibly compromised device.
- Reach the real site yourself: type the official address or get the real app from your app store — don't use the one you just uninstalled and don't tap any related link.
- Change passwords: change your login password and your fund password; if you've used this password elsewhere, change the related accounts too.
- Reset two-factor: register 2FA afresh so any old, possibly leaked verification pairing is invalidated.
- Check logged-in devices: look at logged-in devices in your security settings and kick out every unfamiliar one — a session already logged in won't drop automatically just because you changed your password, so clear it by hand.
- Revoke suspicious API keys: if you've ever connected any third-party tool or created an API key, go in and check for anything unfamiliar or over-permissioned, and delete and recreate anything suspicious. A fake app may have lured you into handing over API details, so don't miss this step.
- Check withdrawals and the whitelist: look for any unfamiliar withdrawal records or any unfamiliar address quietly added to the whitelist, and act at once if you find something off.
- If assets are already gone, treat it as a hack: if a transfer has already happened, the time window is critical — immediately follow hacked-account recovery step by step, freeze whatever can be frozen, and go through the appeal process with the official channel as fast as you can.
FAQ
Is downloading from a phone app store always safe?
An app store is far safer than a download link of unknown origin, but you can't be fully at ease. Fakes do occasionally slip into a store, so when downloading you should still check details like the developer name, the number of reviews and the historical download count — don't install just because the icon and name look right.
Someone sent me an APK installer — can I install it?
Not advisable. A third-party APK of unknown origin, an installer sent in a group chat or a direct message, or a download behind an unfamiliar QR code can all have been turned into a fake app that steals your login, password and codes once installed. To install the Binance app, search your phone's built-in app store for the official developer.
What if I suspect I installed a fake Binance app?
Uninstall the suspicious app first, then on a different device you're sure is clean, type the official address yourself or reach the real site through your app store, change your login and fund passwords, reset two-factor, check for and kick out unfamiliar logged-in devices, and check your withdrawal history for anything odd. If assets are already gone, follow the hacked-account flow as fast as you can.
How do I know what Binance's official developer name and domain actually are?
Defer to Binance's official announcements and what the app store currently shows — don't go on impressions or hearsay. The steadiest approach isn't to compare "does it look alike," but to search your app store and check the developer information, and to reach the site by typing the address yourself or using a bookmark you confirmed earlier, sidestepping every entry point anyone else provides.
Sources
- Binance security page · notes on anti-impersonation and account security (binance.com/en/security, defer to the current official pages)
- Binance official help centre · notes on anti-phishing and official channels (binance.com/en/support)