A fake Binance login page stole your credentials. The attacker logged into your account, changed your withdrawal whitelist, and drained your crypto within minutes. Binance's dedicated Investigations Team can freeze the receiving account — but only if we file the legal request before the attacker withdraws. Every hour matters.
Phishing attacks on Binance users follow a predictable pattern. The attacker creates a website that looks identical to Binance.com — same logo, same colors, same layout. The URL is slightly different: binance-secur1ty.com, binance-verify.net, or binance-login-support.com. The victim receives an email ("Suspicious login detected — verify your account immediately") or a Telegram message from a fake Binance support agent. They click the link, enter their email and password on the fake page, and the attacker captures the credentials in real-time.
The 2FA bypass: If you have Google Authenticator 2FA (which Binance requires for withdrawals), the attacker uses a session hijacking technique. The fake login page asks for your 2FA code. You enter it. The attacker simultaneously submits your email, password, and 2FA code to the real Binance login. They now have an active session on Binance — without ever knowing your 2FA secret. This is why SMS-based 2FA is even more dangerous: the attacker can SIM-swap your phone number and intercept SMS codes entirely.
The withdrawal whitelist attack: Binance has a "whitelist" feature that restricts withdrawals to pre-approved addresses. If this feature is enabled, the attacker must first disable it — which triggers a 24-hour lockout (a security feature Binance added in 2022). If you notice the lockout notification, you have 24 hours to act. If the whitelist was already disabled, the attacker can withdraw immediately.
Why Binance is targeted: Binance is the largest exchange by volume — more users means more phishing targets. Binance's brand recognition makes fake "Binance security alert" emails highly effective. However, Binance's mandatory KYC (since August 2021) means every receiving account is tied to a verified identity — giving us a path to identify the attacker.
Investigations Team: Binance maintains a dedicated Investigations Team that processes legal requests through their law enforcement portal. For phishing cases where stolen funds were sent to a Binance deposit address, the team can: freeze the receiving account, share KYC information with law enforcement, provide transaction records, and flag associated accounts. Binance's team is one of the largest among crypto exchanges — they handle thousands of legal requests annually.
Freeze capability: Binance can freeze the attacker's account within 3-7 business days of receiving a properly formatted legal request with a police report number. For active phishing attacks where funds are still on the platform, Binance can implement emergency restrictions faster (within 24-48 hours) when the request is flagged as urgent.
The whitelist 24-hour window: If the attacker tried to disable your withdrawal whitelist, Binance enforces a 24-hour lockout. During this window, we can file a freeze request on the attacker's receiving account. This is a Binance-specific feature that buys victims critical time — most other exchanges don't have this protection.
KYC disclosure: Binance discloses account holder information (name, government ID, country of residence) to law enforcement or through a court order. The attacker's Binance account is tied to their real identity — they cannot cash out anonymously. Binance has cooperated with the FBI, Europol, and national police forces on multiple phishing and fraud cases.
Chainalysis KYT integration: Binance uses Chainalysis KYT (Know Your Transaction) to screen deposits. If the attacker's Binance deposit address has received funds from known phishing addresses before, Binance's system may have already flagged it. We check whether the account was pre-flagged when filing our request.
A client received an email that appeared to be from Binance: "Security Alert: New Device Login Detected. If this was not you, verify your account immediately." The email contained a link to binance-secure-verify.net — a pixel-perfect copy of Binance's login page. The client entered their email, password, and Google Authenticator 2FA code on the fake page.
The attack: The attacker used the captured credentials to log into the real Binance simultaneously. Within 3 minutes, they added a new withdrawal address (a Binance deposit address under the attacker's KYC), and initiated withdrawals: 2.1 ETH and 12,400 USDT (total ~€85,000). The client received a Binance withdrawal confirmation email but thought it was fake (having just been phished, they didn't trust any Binance emails). They didn't check the actual Binance app.
Our response: The client contacted us 6 hours after the attack. We traced the withdrawal addresses on-chain — both led to a single Binance deposit address. We filed an emergency freeze request with Binance's Investigations Team, including a police report from the client's jurisdiction. Binance froze the attacker's account (containing €65,000 in ETH and USDT) within 48 hours. The remaining €20,000 had been withdrawn to an external wallet before the freeze.
Outcome: 76% recovery (€65,000 of €85,000). The attacker's KYC revealed a resident of Vietnam. Criminal proceedings initiated through Interpol channels. The €20,000 sent to the external wallet was traced to a second exchange — recovery ongoing.
Details anonymized to protect client confidentiality. Swiss professional secrecy applies.
Was your own Binance account also frozen? Binance sometimes restricts victim accounts after phishing attacks — if the attacker used your account to send funds to flagged addresses, your account may be under AML review. Our Binance account unlock practice can resolve this while we trace the stolen funds.
Warning: After a phishing attack, fake "recovery services" will contact you — they may be the same scammers. Read our recovery scam warning before engaging anyone.
Signs: you received an email claiming to be from Binance asking you to "verify your login" or "update security settings," you entered credentials on a page that looked like Binance but had a different URL, you noticed a withdrawal you didn't initiate, your withdrawal whitelist was changed without your action, or your 2FA was triggered without you logging in. Check your Binance withdrawal history in the official app — if there are withdrawals you don't recognize, you were phished.
Generally no — Binance cannot reverse completed withdrawals. However, if the attacker sent stolen funds to another Binance account (which is common — attackers use Binance to cash out), Binance can freeze the receiving account. This is why speed is critical: we need to file the freeze request before the attacker withdraws from the receiving Binance account. If the attacker used an external wallet, we trace on-chain to the next exchange and freeze there.
Yes — Binance enforces a 24-hour lockout when the withdrawal whitelist is disabled. This means the attacker cannot withdraw for 24 hours after disabling the whitelist. If you notice this lockout notification (check your Binance app and email), contact us immediately — we have 24 hours to file a freeze request before the attacker can withdraw. This Binance-specific feature has saved multiple victims.
The attacker didn't bypass your 2FA — they captured your 2FA code through the fake login page and submitted it to the real Binance simultaneously. This is called session hijacking via proxy phishing. Your 2FA secret was never compromised. After the attack: reset your 2FA (generate a new secret), change your password, and review active sessions in Binance security settings. Binance may also require a video verification to restore full account access.
If you didn't enter your email, password, or 2FA code on the fake page, your account is likely safe. However, check: (1) your Binance login history for sessions you don't recognize, (2) your withdrawal whitelist for addresses you didn't add, (3) your API keys for any keys you didn't create. If anything looks wrong, change your password immediately and contact Binance support through the official app.
Binance generally does not reimburse phishing victims — the victim's credentials were compromised, not Binance's systems. However, Binance's Investigations Team actively helps trace and freeze stolen funds on their platform. We focus on tracing and freezing through legal channels rather than seeking reimbursement from Binance. If Binance's own security failed (very rare), different rules apply — but standard phishing cases rely on legal recovery, not exchange reimbursement.
Describe what happened. Include the phishing URL, withdrawal addresses, transaction hashes, and amount stolen. We respond within 6 hours.