Most compromised accounts fail at a switch nobody turned on

Every few weeks a reader writes to me after losing an exchange account. Almost none of those stories start with a cracked password. Logging in is already wrapped in several layers of risk checks, and brute force is not where the money is. The pattern is duller and much more common: an email that looked exactly right, a search ad sitting above the real domain, a session left open on a borrowed laptop. Nobody had to break into Binance. They only had to fool one person.

Which is why the useful picture is not a single very strong lock. It is a row of ordinary doors. Each one is beatable on its own. Put them in a line and an attacker has to win four or five times in a row, and almost nobody manages that.

Seven layers follow, in the order I would set them: the ones available the minute you register come first, the manual check you do at the moment money leaves comes last. All seven take somewhere between twenty and thirty minutes. Binance publishes a short version of the same advice, five ways to improve your Binance account security, and it is worth reading alongside this one. What is below is longer, and it stops on the parts the official page covers in a sentence.

Before you start

None of these is a master lock. The anti-phishing code stops fake email. The allowlist stops someone who is already inside. Hard two-factor stops credential stuffing. Each covers one stretch of road, which is the whole reason the answer is seven rather than one.

Layer one · a dedicated email and a password used exactly once

This is the layer people skip because it sounds too obvious. The exchange account gets the same address that receives shopping receipts and newsletters, paired with a password that also opens two other sites. The problem is arithmetic. Data breaches happen constantly, and the moment one of your pairs turns up in a dump, somebody will replay that pair against every large exchange in an afternoon. Credential stuffing is cheap, and it works often enough to be worth running at scale.

Two moves close the hole. Register a separate address you use for exchanges and almost nothing else — not for shopping, not on any public profile. Then let a password manager generate the password, and let that password exist in exactly one place. Do not invent one yourself. Human-invented passwords cluster into patterns that cracking dictionaries finished mapping years ago.

One clarification while we are here: a login password is not a second factor. It is the door handle. Everything below is where the difference actually shows up.

Layer two · two-factor that does not rely on your phone number

You almost certainly have two-factor switched on already. The question is which kind.

If the second factor is an SMS code, demote it to a fallback and promote something harder. SMS loses to the SIM swap: an attacker gathers enough personal detail to talk your carrier into issuing a replacement SIM for your number. The instant that port goes through, the codes arrive on their handset and yours goes quiet. In crypto this stopped being an exotic attack a long time ago.

Ranked from workable to best: a TOTP code from an authenticator app such as Google Authenticator or Authy is generated on your device and owes nothing to your carrier. Above that sit passkeys and a hardware security key like a YubiKey, where the credential is bound to a physical object and a phishing page has nothing to capture. Binance supports all of them.

Two other pieces go deeper into this layer: The truth about 2FA · why SMS is not safe ranks the five kinds of second factor by real defensive strength, and Passkeys in 90 seconds explains what makes a passkey different. If the vocabulary is new, the glossary entries for 2FA and passkey are a minute each.

The step everyone forgets

When you turn on TOTP, Binance shows you a long backup key once, on the same screen as the QR code. Depending on the version you are looking at, the label reads something like secret key or recovery key. Write it down somewhere that is not the phone. If the handset goes swimming or the app disappears with your old device, that string is the only way to rebuild the authenticator elsewhere. A screenshot saved on the same phone is not a backup.

Layer three · the anti-phishing code

Badly underrated, and the cheapest minute on this list.

The trick behind it is neat. You choose a short string of your own, and from that point every genuine email Binance sends you carries it. The mass-mailed fake — unusual activity on your account, click here to verify — cannot carry it, because whoever sent it has no idea what you picked. Telling real from fake collapses into a single glance: is my string in this message? If not, delete and move on.

It lives under account security, in the block usually labelled advanced security; in the app it sits one level below the two-factor screen, so keep scrolling past the switches you already recognise. Choose something you will spot instantly and nobody would guess. The field accepts roughly four to twenty characters, though the exact limits are printed next to the box and change between versions, so go by what the page shows you (checked September 2026). After that, one rule with no exceptions: the code appears only in mail Binance sends to you. Anybody who asks you for it, however politely and however convincingly they present themselves as support, is running a scam.

Layer four · the withdrawal allowlist

Everything so far has been about keeping people out. This layer assumes one of them got in anyway and makes sure the coins still cannot leave.

With the allowlist on, withdrawals only go to addresses you added and verified beforehand. Put your own wallet and your deposit address at a second venue on it once, and ordinary withdrawals feel no different afterwards. What gets stopped is precisely what a thief wants to do — push a large balance to a fresh address immediately — because that address is not on the list, and adding one means clearing two-factor and email confirmation again, then sitting through a hold.

Two companion settings are worth opening while you are there. The address security restriction freezes a newly added address for a period before anything can be sent to it, and that window is your chance to notice something has gone wrong; how long it runs is set by Binance and displayed when you add the address, so read it off the screen rather than trusting a number from an article (checked September 2026). The other is quick withdrawal, which waives the second check for small amounts going to allowlisted addresses. Reasonable people differ here and the convenience is real; I leave it off, because verifying twice costs me seconds and I would rather not learn what the exception costs. The withdrawal whitelist glossary entry has the mechanics.

How mine is set up

Three or four addresses on the list, restriction on, and it has stayed that way for years. It earned its keep on an evening when I signed in from a machine I do not normally use and a browser extension started behaving oddly. What let me finish calmly was knowing the shape of the worst case: even with that machine compromised and the session stolen, the coins could only travel to addresses I already own. Not zero risk. A ceiling on it, which is a different and more achievable thing.

Layer five · devices, sessions and API keys

Security is not only about the moment you sign in. It is also about what stays behind afterwards. Three lists in the security settings deserve a visit every few months.

Device management shows everything that has ever signed in to the account. Remove anything you do not recognise, and anything you retired — the old phone, the laptop from a previous job. Account activity gives you recent logins with time, address and region; a line you cannot account for means change the password first and investigate second. Then API keys. If you have ever run a trading bot, a copy-trading tool or a portfolio tracker, it asked you for one. Delete the keys you no longer use. An old key with withdrawal permission still attached is a back door whose owner has forgotten it exists.

The same habit belongs on-chain, where stale token approvals sit around for years for identical reasons: permissions pile up and hardly anyone goes back to prune them. The method is in Checking and revoking token approvals. On the exchange side it is simply devices, keys and sessions, on a calendar.

Layer six · the habits that beat phishing

The first five are settings. You do them once. This one is a habit, and it has to travel with you, because no switch helps when the account holder types real credentials into a convincing fake. That is how the overwhelming majority of these losses actually end.

  • Reach the site through a bookmark, never through search. Someone is usually buying ad placement on lookalike domains, which means the top result labelled as the exchange may not be the exchange. Type the domain by hand once, bookmark it, and use the bookmark from then on.
  • Never follow a link from email, SMS or a direct message to log in. If a message says something needs your attention, open the bookmark and check the account yourself. Combined with the anti-phishing code, that pair of habits removes most of the surface fake email is aiming at.
  • Nobody official calls you first. Any caller claiming to be Binance support who wants you to move funds to a safe account, read out a code from your screen, or install remote-access software so they can help, is running a script. A real one is walked through in the fake support call that cost 2.3 BTC.

The catalogue is far longer than three items: fake airdrops, fake approval pop-ups, cloned apps, impersonated staff. I collected the ones circulating this year in the crypto phishing scam atlas, 2026 edition, each with a real case and the one detail that gives it away, and it reads well immediately after this section.

Layer seven · two checks before you press withdraw

The last layer lands at the moment money actually moves. The first six protect the account. This one protects you from your own hands. A broadcast transaction is final and no support desk can pull it back, for reasons laid out in whether a mistyped withdrawal address can be recovered. So two things, every time, without getting bored of them.

One, read the address properly. After pasting, compare the opening characters and the closing characters against the source instead of glancing at the general shape. Clipboard malware that silently swaps crypto addresses on paste has been around for years, and it survives on the fact that every address looks like every other address at a glance.

Two, send a test amount first. Whenever an address is new to you, move a small amount, wait for it to land, confirm it arrived where you meant it to, then send the rest. The extra network fee is the price of certainty, and it is not the line item to economise on.

The other frequent way withdrawals go wrong is the network selector. The same ticker on a different chain is a different contract, and choosing the wrong one can leave the transfer somewhere you cannot reach; USDT on the wrong network covers what is still recoverable. Check the network in the same breath as the address.

Why count withdrawing as part of account security at all? Because it is the step where an asset stops depending on one company staying solvent. However carefully the settings are arranged, coins sitting in the account are still in somebody else's custody.

The seven layers at a glance

The same seven in one table: what each one blocks, and roughly what it costs in time. Work down it with the Binance security page open in another tab and tick them off.

Layer What it mainly blocks Rough time
Dedicated email and a unique password Credential stuffing, password reuse 5 to 10 minutes
Two-factor, moved off SMS Replayed credentials, SIM swap 3 to 5 minutes
Anti-phishing code Email impersonating the exchange Under a minute
Withdrawal allowlist Funds leaving after a takeover 5 to 10 minutes
Devices, sessions and API keys Leftover logins, forgotten API back doors A few minutes, every few months
Anti-phishing habits Fake sites, fake support, fake links Permanent, not a one-off
Two checks before withdrawing Wrong address, wrong network, clipboard malware About a minute per withdrawal
On the numbers above

The times are there to set expectations, nothing more. Menu names and the exact location of each setting differ between the web version and the app, and they move between releases, so treat the page in front of you as authoritative (checked September 2026). When an option is not where this article says it is, searching the Binance help centre for its name is faster than hunting through menus.

Common questions

Do I really need the anti-phishing code, and what happens if I skip it?

Set it. The anti-phishing code is a short string you choose, and once it is on, every genuine email from Binance carries it. A mass-mailed fake cannot carry it, because whoever sent it has no idea what you picked, so telling real from fake becomes a single glance at the message. Skip it and you are left comparing a forged account alert against a real one by eye, which is exactly the comparison those emails are built to win. It does not stop every attack. It does close the most common one, and the whole cost is a minute and a string you will remember.

If I turn on the withdrawal allowlist, will an urgent withdrawal become painful?

No, provided you set it up before you need it. The rule is simple: coins can only leave to an address you added and verified in advance. Put your regular destinations on the list once and ordinary withdrawals feel unchanged. What the list blocks is a large transfer to a brand new address right now, which happens to be the first thing a thief reaches for. When you genuinely need a new destination, add it ahead of time and wait out the hold rather than switching the allowlist off for one transfer, because switching it off removes the only layer that still works once somebody is already inside the account. The waiting buys you the certainty that a stolen session cannot send your balance anywhere you do not own.

Is SMS two-factor still usable in 2026?

Usable, but not as your main factor. Its weak point is the SIM swap: somebody collects enough personal detail to persuade your carrier to move your number onto a SIM they hold, and from that moment the codes land on their phone rather than yours. A code from an authenticator app never leaves your device, and a passkey or a hardware key raises the bar further by tying the credential to a physical object. Keep SMS as a fallback method if the platform wants one, but move the primary second factor onto something that does not depend on a phone number.

If every security setting is done, are my coins safe on the exchange?

Doing all of it sharply reduces the odds that an attack aimed at you personally succeeds, whether that is phishing, account takeover or social engineering. It does nothing about risk at the platform level: the company itself running into trouble, a regulator freezing activity, withdrawals paused in a violent market. That is where the old line still holds, not your keys, not your coins. Keeping trading money and spending money on an exchange is perfectly normal. For an amount you plan to leave untouched for years, the safer home is a wallet whose private key you hold yourself. Those two are a division of labour rather than a contradiction.

Last word

There is no single move that settles account security. It is seven unremarkable switches stacked into something with depth. Individually none of them looks impressive, but an attacker has to get past the email, the second factor, the anti-phishing code and the allowlist in sequence, and most attempts run out of road somewhere around the third or fourth.

If today allows exactly one action, go and set the anti-phishing code. A minute, and the best return per minute on the list. Then work through the rest in order when you have a free evening.

Setting all seven blocks the attacks aimed at you as a person. Platform-level risk is a different animal, and the old line covers it: not your keys, not your coins. An exchange is a doorway, not a vault.

On which money belongs on an exchange and which should move out, Cold wallet vs hot wallet lays out a split you can actually keep to; for judging whether a platform deserves custody of anything at all, How to evaluate a crypto exchange before you deposit gives you six things you can check yourself.