Fraud Recovery · Phishing · Binance
Act fast

Phishing on Binance?
We trace and freeze.

A fake Binance login page stole your credentials. The attacker logged into your account, changed your withdrawal whitelist, and drained your crypto within minutes. Binance's dedicated Investigations Team can freeze the receiving account — but only if we file the legal request before the attacker withdraws. Every hour matters.

◉ Swiss licensed lawyers◉ Blockchain forensics◉ Binance Investigations Team
How it works

How phishing works on Binance

Phishing attacks on Binance users follow a predictable pattern. The attacker creates a website that looks identical to Binance.com — same logo, same colors, same layout. The URL is slightly different: binance-secur1ty.com, binance-verify.net, or binance-login-support.com. The victim receives an email ("Suspicious login detected — verify your account immediately") or a Telegram message from a fake Binance support agent. They click the link, enter their email and password on the fake page, and the attacker captures the credentials in real-time.

The 2FA bypass: If you have Google Authenticator 2FA (which Binance requires for withdrawals), the attacker uses a session hijacking technique. The fake login page asks for your 2FA code. You enter it. The attacker simultaneously submits your email, password, and 2FA code to the real Binance login. They now have an active session on Binance — without ever knowing your 2FA secret. This is why SMS-based 2FA is even more dangerous: the attacker can SIM-swap your phone number and intercept SMS codes entirely.

The withdrawal whitelist attack: Binance has a "whitelist" feature that restricts withdrawals to pre-approved addresses. If this feature is enabled, the attacker must first disable it — which triggers a 24-hour lockout (a security feature Binance added in 2022). If you notice the lockout notification, you have 24 hours to act. If the whitelist was already disabled, the attacker can withdraw immediately.

Why Binance is targeted: Binance is the largest exchange by volume — more users means more phishing targets. Binance's brand recognition makes fake "Binance security alert" emails highly effective. However, Binance's mandatory KYC (since August 2021) means every receiving account is tied to a verified identity — giving us a path to identify the attacker.

Binance response

How Binance handles phishing cases

Investigations Team: Binance maintains a dedicated Investigations Team that processes legal requests through their law enforcement portal. For phishing cases where stolen funds were sent to a Binance deposit address, the team can: freeze the receiving account, share KYC information with law enforcement, provide transaction records, and flag associated accounts. Binance's team is one of the largest among crypto exchanges — they handle thousands of legal requests annually.

Freeze capability: Binance can freeze the attacker's account within 3-7 business days of receiving a properly formatted legal request with a police report number. For active phishing attacks where funds are still on the platform, Binance can implement emergency restrictions faster (within 24-48 hours) when the request is flagged as urgent.

The whitelist 24-hour window: If the attacker tried to disable your withdrawal whitelist, Binance enforces a 24-hour lockout. During this window, we can file a freeze request on the attacker's receiving account. This is a Binance-specific feature that buys victims critical time — most other exchanges don't have this protection.

KYC disclosure: Binance discloses account holder information (name, government ID, country of residence) to law enforcement or through a court order. The attacker's Binance account is tied to their real identity — they cannot cash out anonymously. Binance has cooperated with the FBI, Europol, and national police forces on multiple phishing and fraud cases.

Chainalysis KYT integration: Binance uses Chainalysis KYT (Know Your Transaction) to screen deposits. If the attacker's Binance deposit address has received funds from known phishing addresses before, Binance's system may have already flagged it. We check whether the account was pre-flagged when filing our request.

Step by step

Our recovery process for Binance phishing

  • 1. Immediate damage control (0-2h): If you still have access to your Binance account: change your password, disable the attacker's withdrawal addresses, enable authenticator-based 2FA (not SMS), and check your withdrawal history. If you've lost access: Binance support can freeze your account from their side — contact them through the official Binance app (not a web search link).
  • 2. Blockchain tracing (2-48h): We trace the stolen funds from your Binance withdrawal address on-chain. Binance generates unique withdrawal addresses per transaction — we identify where the attacker sent the funds next. If they sent to another Binance account, we file a freeze request. If they sent to an external wallet, we trace through Chainalysis and Elliptic until we find a freezing opportunity.
  • 3. Emergency freeze request (3-7 days): We file a legal request with Binance's Investigations Team alongside a police report. The request includes: blockchain evidence (TX hashes, wallet addresses), proof of phishing (fake website URL, email headers), and the Binance deposit address that received stolen funds. Binance typically responds within 3-7 business days.
  • 4. Identity and recovery (2-12 weeks): Through legal process, we obtain the attacker's Binance KYC. With the identity known and funds frozen, we pursue civil recovery or coordinate criminal proceedings with law enforcement in the attacker's jurisdiction.
Real case

Case: Binance phishing with 2FA bypass

A client received an email that appeared to be from Binance: "Security Alert: New Device Login Detected. If this was not you, verify your account immediately." The email contained a link to binance-secure-verify.net — a pixel-perfect copy of Binance's login page. The client entered their email, password, and Google Authenticator 2FA code on the fake page.

The attack: The attacker used the captured credentials to log into the real Binance simultaneously. Within 3 minutes, they added a new withdrawal address (a Binance deposit address under the attacker's KYC), and initiated withdrawals: 2.1 ETH and 12,400 USDT (total ~€85,000). The client received a Binance withdrawal confirmation email but thought it was fake (having just been phished, they didn't trust any Binance emails). They didn't check the actual Binance app.

Our response: The client contacted us 6 hours after the attack. We traced the withdrawal addresses on-chain — both led to a single Binance deposit address. We filed an emergency freeze request with Binance's Investigations Team, including a police report from the client's jurisdiction. Binance froze the attacker's account (containing €65,000 in ETH and USDT) within 48 hours. The remaining €20,000 had been withdrawn to an external wallet before the freeze.

Outcome: 76% recovery (€65,000 of €85,000). The attacker's KYC revealed a resident of Vietnam. Criminal proceedings initiated through Interpol channels. The €20,000 sent to the external wallet was traced to a second exchange — recovery ongoing.

Details anonymized to protect client confidentiality. Swiss professional secrecy applies.

Was your own Binance account also frozen? Binance sometimes restricts victim accounts after phishing attacks — if the attacker used your account to send funds to flagged addresses, your account may be under AML review. Our Binance account unlock practice can resolve this while we trace the stolen funds.

Warning: After a phishing attack, fake "recovery services" will contact you — they may be the same scammers. Read our recovery scam warning before engaging anyone.

FAQ

Phishing on Binance — questions

How do I know if I was phished on Binance?

Signs: you received an email claiming to be from Binance asking you to "verify your login" or "update security settings," you entered credentials on a page that looked like Binance but had a different URL, you noticed a withdrawal you didn't initiate, your withdrawal whitelist was changed without your action, or your 2FA was triggered without you logging in. Check your Binance withdrawal history in the official app — if there are withdrawals you don't recognize, you were phished.

Can Binance reverse a phishing withdrawal?

Generally no — Binance cannot reverse completed withdrawals. However, if the attacker sent stolen funds to another Binance account (which is common — attackers use Binance to cash out), Binance can freeze the receiving account. This is why speed is critical: we need to file the freeze request before the attacker withdraws from the receiving Binance account. If the attacker used an external wallet, we trace on-chain to the next exchange and freeze there.

The attacker disabled my Binance withdrawal whitelist. Do I have 24 hours?

Yes — Binance enforces a 24-hour lockout when the withdrawal whitelist is disabled. This means the attacker cannot withdraw for 24 hours after disabling the whitelist. If you notice this lockout notification (check your Binance app and email), contact us immediately — we have 24 hours to file a freeze request before the attacker can withdraw. This Binance-specific feature has saved multiple victims.

What if the attacker used Google Authenticator 2FA bypass?

The attacker didn't bypass your 2FA — they captured your 2FA code through the fake login page and submitted it to the real Binance simultaneously. This is called session hijacking via proxy phishing. Your 2FA secret was never compromised. After the attack: reset your 2FA (generate a new secret), change your password, and review active sessions in Binance security settings. Binance may also require a video verification to restore full account access.

I clicked a fake Binance link but didn't enter anything. Am I safe?

If you didn't enter your email, password, or 2FA code on the fake page, your account is likely safe. However, check: (1) your Binance login history for sessions you don't recognize, (2) your withdrawal whitelist for addresses you didn't add, (3) your API keys for any keys you didn't create. If anything looks wrong, change your password immediately and contact Binance support through the official app.

Does Binance reimburse phishing victims?

Binance generally does not reimburse phishing victims — the victim's credentials were compromised, not Binance's systems. However, Binance's Investigations Team actively helps trace and freeze stolen funds on their platform. We focus on tracing and freezing through legal channels rather than seeking reimbursement from Binance. If Binance's own security failed (very rare), different rules apply — but standard phishing cases rely on legal recovery, not exchange reimbursement.

Related

Other scams on Binance

Investment Fraud
Fake platforms · Ponzi
Rug Pull
Liquidity drain · token dump
Pig Butchering
Romance-driven fake investment
SIM Swap
Phone hijack → Binance drain

Phishing on other platforms

Bybit
Coinbase
Kraken
OKX
KuCoin
MEXC
Bitfinex
ALL PLATFORMS →
REPORT NOW

Phishing on Binance?
Every hour counts.

Describe what happened. Include the phishing URL, withdrawal addresses, transaction hashes, and amount stolen. We respond within 6 hours.

Swiss lawyersBlockchain forensicsBinance Investigations Team