How to tell whether a "Binance" message is real
An email, a text, a phone call, a DM — each says it's "Binance", each says something's up with your account, and each wants you to click the link now, confirm now, read out the code now. At moments like this, the dangerous part isn't the message itself but the sense of "hurry" it manufactures. This piece gives you a way to verify that doesn't rely on gut feeling: three steps to tell real from fake, plus one fallback for "when you really can't tell, do this". Commit it to memory, and next time the pressure's on you'll keep a steady hand instead of clicking blindly.
The three-step check: anti-phishing code → domain → wording
When a message claims to be Binance, run through it in this order. Any single step turning red is enough to call it fake — you don't have to finish all three.
Step one: look for the anti-phishing code (works for email and on-site messages only)
If you've already set an anti-phishing code, then a genuine Binance email or on-site message will carry the string you set. This is the easiest check of all: if the email doesn't contain your anti-phishing code, or the code is wrong, treat it as fake straight away. Note that it only covers email and on-site messages — texts, calls and third-party DMs have no anti-phishing code, so this step doesn't apply to them and you move on to steps two and three.
Step two: check the sender / link domain
For an email, look at the real sender address, not the display name. The display name can be set to anything, like "Binance Security Centre"; whether it's genuine comes down to whether the domain after the @ is the official one. Common impersonation tricks: swapping in a look-alike domain, adding a prefix or suffix, or using a very long subdomain that puts the official word up front to fool you.
- Look after the @: the domain of the sender address is what matters; don't be taken in by the display name.
- Check where the link lands: hover over the button or link in the email (don't click yet) and read the real URL that pops up at the bottom left. If the text says "official Binance site" but the link points to an unfamiliar domain, it's phishing.
- Be wary of look-alike domains: one extra letter, a different suffix, or the official word buried in a long string of a domain — these are all common impersonation tricks.
When deciding on the official domain, defer to what Binance's own pages currently publish, not your impression. The safest approach isn't to compare how similar the domains look, but simply not to click the link and to go to the site yourself (see section four below).
Step three: read the wording
Phishing messages share a certain flavour of tone: they manufacture urgency, push you to act at once, and steer you towards "entering sensitive information" or "making a transfer". If even one of the lines below shows up, be on high alert:
- "Account anomaly / about to be frozen / risk detected — click to verify immediately."
- "Your withdrawal request is pending confirmation; if this wasn't you, click here to cancel."
- "Support is handling your issue — please provide the code / read out the code in this text to me."
- "To join the official event / airdrop, first send a transfer to a specified address to unlock it."
Things the real Binance never does
Remembering "what the official Binance won't do" is more useful than remembering "what it will do" — precisely because scammers love to pose as the official Binance and do exactly these things. Run into any of the following and you can more or less call it fake:
- It won't message you first: it won't add you or DM you on Telegram, WeChat, WhatsApp or other third-party chat apps saying "I'm official support". You reach official support by going into the official app or website yourself; it doesn't come "camping" on you.
- It won't ask you for a password or a code: it won't request your login password, fund password, two-factor code or seed phrase. Those are for you to enter on the official pages yourself, and no "support agent" needs you to read them out. The seed phrase especially — anyone telling you to "back up", "verify" or "import" your seed phrase is running a scam, and once it's out, on-chain assets are almost impossible to recover.
- It won't have you transfer money to "verify" or "unfreeze": there's no such thing as "send a transfer first to prove the account is safe" — that's pure scam talk.
- It won't have you move coins to a "safe address": the line "your account is under attack, move your assets to the safe address / cold wallet we give you for now" has been one of the most convincing and most costly tricks of the past couple of years — that address is the scammer's, and coins sent there never come back. To actually protect your assets, you do it yourself inside your account; the "official Binance" never provides an external address for you to send to.
- It won't have you install remote-control software: it won't ask you to install remote-assistance programs like AnyDesk or TeamViewer to "help sort it out". Once it's installed and you've granted control, the other side can operate directly on your screen and watch you type your codes. Anyone getting you to install a "remote assistance" or "security check" tool — hang up / block on the spot.
- It won't have you download an app via a private link: getting you to click some link to install a "new version" or "secure version" is most likely an impersonation. To install the app, search for the official developer in your phone's system app store; for how to check, see how to confirm the Binance app you downloaded is real.
Fake support, fake texts, fake calls
Each channel has its own tells, so let's take them one at a time.
The fake support DM
What they say: you post "I can't log in / can't withdraw" on a social platform or in a group, and straight away someone with a profile reading "Binance official support" DMs you: "I saw your issue, let me help you sort it out", even rattling off a few bits of official jargon to seem professional.
Why they say it: they lie in wait for people who are anxious and eager for help — the more panicked you are, the more easily you follow along. What they're really after is to lead you to click a link, install a "remote assistance" program, or coax a code out of you step by step. Real support doesn't go around DMing and stalking people like this.
What you should do: don't reply, don't click, don't add them. If you have a problem, go into the official app or website yourself and start an enquiry from the support entry inside it — that's the only trustworthy support channel. Treat any support that "comes to you first" as fake to begin with.
The fake text
What they say: a text from a number that looks like a legitimate one, reading "[Binance] Your withdrawal request has been submitted; if this wasn't you, click xxx to cancel" or "Your account is at risk, click to verify", followed by a shortened link.
Why they say it: a text has no anti-phishing code, so step one's check can't be used, and that's exactly the gap scammers exploit. The shortened link leads to a high-fidelity fake login page, and the moment you enter your login it lands in their hands; another version impersonates a "verification code text" and lures you into forwarding the code you received to "support to check".
What you should do: never click a link in a text — to check something, go to the site yourself; and never, under any circumstances, forward or read out any code you receive to anyone. If there really is a withdrawal or a risk, logging in to the official site will tell you.
The fake call
What they say: the voice on the line claims to be "Binance security / the support centre", urgent yet professional: "we've detected an unusual login on your account, it's being hijacked, I'll freeze it for you right now — please read out the text code you just received" or "please move your assets to a safe address for now, as I tell you".
Why they say it: caller ID can be spoofed, and a line like "it's being hijacked" is designed to create panic so you do as told before you can think it through. What they want is the string of code you speak aloud, or to trick you into moving the coins yourself.
What you should do: the moment the voice asks for a code, a password, or tells you to transfer money / install software, hang up. Don't let yourself be swept along on the call, and don't call back the number it gives. To confirm your account status, hang up and go to the site yourself to check the login records and withdrawal records.
Not sure? Go to the site yourself
Of all the checks, the one least likely to go wrong is actually this, so simple it barely takes any thought: don't click any link in the message, don't call back the number it gives, don't scan any code — open your browser bookmark or type the official address yourself, log in to your account, and check on-site whether the thing is actually there.
The logic is direct: if what the message says is true (say there really is a withdrawal, or a genuine unusual login), then logging in to the official site, you'll find it in the notifications or security records; if there's no such entry on the site, the message is most likely fake, its whole aim being to trick you onto a fake page. This fallback holds up because it bypasses the entry point the other side provided entirely — you take the route you control and know for sure is official.
- Go in via a bookmark or the system app: save the official Binance address as a browser bookmark in advance and always enter through the bookmark from then on, not through a search and not by clicking a link; entering via the official app installed from your phone's system app store is reliable in the same way. Neither route passes through the entry point the other side gave you.
- Reconcile on-site: once you're in, look at the on-site message centre and the login records and withdrawal records under security settings, and match them against what the suspicious message claimed. If it says "there's an unusual login", check whether it's in your login devices; if it says "there's a withdrawal pending confirmation", check whether it's in your withdrawal records.
- If it's not there, it's fake: if there's simply no sign on the site of what the message mentions, you can basically call the message fake — delete it, ignore it, and certainly don't go back and click it.
Once you make this a habit, the earlier three-step check mostly helps you "see through it early", while this one is the "won't be led astray no matter what" safety net. It's a bit slower, a bit plodding — but it's exactly that plodding quality that stops the scammer's carefully engineered "hurry" from gaining any traction. If you've already entered a password or code on a suspicious page, don't delay: follow the order in rescuing a hacked account to change your password, check your devices and limit the damage as fast as you can.
A few convincing playbooks
Cross-referencing the official security tips and publicly reported cases, here are a few high-fidelity ones that easily catch people out, so you can get your guard up in advance:
- The "unusual login" emergency brake: an email says there was a login from another location, paired with a "not me, freeze it now" button that leads to a fake login page.
- The "withdrawal pending" reverse move: it tells you there's a withdrawal and steers you to click "cancel", coaxing your code out of you along the way.
- The "official event / airdrop" transfer-first ploy: it has you send a transfer to a specified address to "activate" before you can claim.
FAQ
Will the real Binance DM me out of the blue and ask for my password or a code?
No. The real Binance won't message you first on a third-party chat app, and it won't ask you for your login password, fund password or two-factor code. Treat anyone who asks you for these as a scammer, whatever identity they claim.
If an email has my anti-phishing code, does that make it genuine?
A matching anti-phishing code is a strong sign an email is genuine, but it's still best not to act on links inside the email directly. Get into the habit of typing the official address yourself or going in via a bookmark, and treat the email as a notice, not as a place to take action.
When you can't tell whether a message is real, what's the safest thing to do?
Don't click any link in the message, don't call back the number on it, and don't scan any code. Open your browser bookmark or type the official address yourself, log in, and check the on-site notifications or security records to see whether the thing is really there. If it is, the site will show it; if it isn't, it's most likely fake.
I've clicked the link but didn't enter anything — does it matter?
If you only opened the page and entered no login or code, the risk is relatively small. To be safe, go to the official site yourself, change your login password once, and take a look at whether there are any unfamiliar devices in your login list. If you did enter a password or code, deal with it as soon as possible following rescuing a hacked account.
Sources
- Binance security page · anti-phishing and account security notes (binance.com/en/security, defer to the current official page)
- Binance official Help Center · anti-fraud entries (binance.com/en/support)