Why a hodler still cannot avoid an exchange account

Conclusion first: for a long-term holder, a centralized exchange account is a necessary channel, not the place the assets should sit. Those two halves do not contradict each other, but plenty of guides only write the first one, and they write it as if opening the account were the finish line.

Here is how I use mine: the account has been sitting there for years, and the balance has been low for years. It carries a handful of jobs that are awkward to do any other way.

The first is fiat in and out. An on-chain wallet does not take a bank card. Your salary, your bonus, the money from selling part of a stock position — turning any of it into an on-chain asset requires one fiat-to-crypto step somewhere. In reverse: the day you need to pull some out for rent, for a medical bill, for a child's tuition, you also need an exit that turns coins back into fiat and lands it in a bank account. You do not use that exit most of the time, but it has to be open, and it has to be one you have verified works. Plenty of people attempt their first cash-out on the day they urgently need the money, and then get stuck in a risk-control review. That is the worst possible timing.

The second is swapping between assets. Holding long term does not mean you never touch anything again. You might want to move part of an altcoin position back into BTC, or park some profit in a stablecoin. A decentralized exchange can do that, of course, but it asks you to manage gas yourself, manage token approvals yourself, and judge for yourself whether a contract is genuine — precisely the places where an ordinary holder is most likely to come off the rails (I have written that part up in Checking and Revoking Token Approvals). For someone who just wants to sit still, doing the swap in a deep centralized order book and then withdrawing is a shorter path with fewer places to trip.

The third is the small set of operations you cannot route around. Some tokens have gone through a contract migration or a token swap where the exchange handled the conversion window; some chains need a pile of node configuration on the wallet side, and going through an exchange is simply cleaner. You run into this maybe once or twice a year, but when you do, you need the account to already exist.

The fourth one almost nobody wants to say out loud: an account has a recovery process, self-custody does not. Lose the hardware wallet, burn the seed phrase, and nobody on earth can help you. An exchange account at least has identity verification and an appeals channel. I am not saying that is a reason to keep coins on a platform. I am saying that when you are arranging your estate, an account a family member can claim with identity documents is sometimes a more realistic backstop than a seed card hidden inside a book. Both paths can stay open; they do not conflict. I went into this in how to leave your coins to your children.

Now the other half. The balance you see on an exchange is a row in that company's database, not coins in your hands. Whether that row can be redeemed depends on whether the company is still able to operate. In the 2022 round, users at certain platforms could see their balance on the web page while the withdraw button did nothing — the number sat there, the money would not come out. Industry transparency did improve afterwards (proof of reserves became standard; see the proof of reserves entry), but the structural problem did not change: if the private key is not yours, what you hold is a counterparty promise.

Where this article stands

Every step below is written toward one goal: get this account usable quickly, leave as little exposure as possible, and then get your coins out of it as soon as you can. If you finish reading and conclude that you should park a large sum on an exchange long term, then I wrote it badly.

Decide first how wide this door needs to be

Before you click sign up, spend ten minutes on three questions. The three answers decide how you set everything that follows.

Question one: roughly how much money will move through it in a year? Buying two or three times a year, a few hundred at a time, is a completely different account from a monthly buy that also needs the occasional cash-out. The first can be locked down hard — one address on the allowlist, full verification on every withdrawal. The second may need a little more operating room, and in exchange you have to look at device management and login history more often.

Question two: could you absorb the balance in this account going to zero? That is not a scare question, it is a quantitative standard. The number you come up with is the ceiling on what you allow to sit in the account long term. Above that number, move it out. My own standard is crude: an amount that would sting for a while if it vanished, but would not affect the next six months of my life.

Question three: where is your long-term stack going to live? This is the one most often skipped and the one with the largest consequences. Plenty of people go in this order: open the account, buy the coins, then discover there is nowhere to put them, so they stay on the exchange — and stay there for two years. The correct order is the reverse: get the self-custody wallet ready and its backup verified first, then go open the exchange account. That way, from your very first purchase, there is a destination.

Which wallet form suits you depends on the amount and on how often you plan to touch it. These two are the bedrock of this site: The complete wallet guide lays custodial, non-custodial, cold and hot side by side; Cold vs hot wallet gives you a way to split the stack — which part belongs on the exchange and which part belongs in a hardware wallet is covered there in more detail than here.

If you have already decided to buy a hardware wallet, glance at the hardware wallet comparison and the hardware wallet spec matrix while you are at it, rather than scrambling on the day you sign up. A hardware wallet takes a few days to arrive, which happens to run in parallel with the KYC review wait.

What to have ready before you sign up

Get these few things ready first and the sign-up goes much more smoothly, while a few holes that are hard to patch later never open at all.

An email address that barely exists in public

Do not use the everyday address you register everywhere with and receive every newsletter on. Open a separate one for the exchange: never use it on a forum, never type it into a giveaway form, never post it on social media. The reason is direct. Once an address leaks, you start receiving targeted phishing mail, and those templates get better at looking real every year. An address that has never appeared anywhere is itself a layer of filtering.

That mailbox needs two-factor of its own, and preferably not the same method on the same device as the exchange — if the mailbox falls, the exchange's email confirmations are worth nothing.

A long password used exactly once

Generate it in a password manager, do not invent it. Passwords out of a human head have patterns, and the dictionaries went through those patterns long ago. What matters more is not reusing it: if you have ever used this email-and-password pair on a site that later got breached, an attacker will take the pair and try it on every major exchange in turn. That is credential stuffing, it costs almost nothing to run, and it is the single most common way accounts fall.

A phone number you can keep for years

Changing a phone number is a nuisance inside an exchange's system, especially once you are no longer in the country the number came from. Pick one you are sure you will not give up for the next few years. And note this: the phone number is the weakest link among your verification methods, because someone can take your personal details to the carrier and have your SIM reissued to them (SIM swap). Keep it as a fallback, do not make it your main one.

An authenticator app, and a decision about where its backup key lives

Install the authenticator app before you sign up (Google Authenticator, Authy, anything of that kind). The part to think through in advance is this: when you enable it, the platform hands you a backup key, and you need to know where that string is going to live. In a screenshot on the same phone is the same as nowhere — lose the phone and you lose both at once. Copied onto paper and stored apart from your seed phrase is the least troublesome answer. The reasoning behind this layer is spelled out in The truth about 2FA and why SMS is not safe and Passkeys in 90 seconds.

Your ID document, and how your name is actually spelled

Have a valid identity document ready, ideally with more than six months left on it. Which types are accepted — passport, national ID, driving licence — and whether an extra proof of address is needed varies by region; go by what your own account page lists.

One trap deserves its own line: the name you type at sign-up has to match the one printed on the document exactly. That includes how the given names are split, whether there is a hyphen, whether the middle name is included. Plenty of people type whatever spelling they habitually use, then fail to match at the KYC step and have to go through a manual correction process, which is slow and annoying.

Confirm the service is actually available where you are

This is the thing most worth confirming before you open an account and the thing most often skipped. Different jurisdictions treat crypto trading platforms very differently, and the same platform offers different services in different places. No article can settle this for you once and for all — the rules keep moving — so you need to read what the sign-up page and the platform's terms of service currently say about your region.

What I would not do is use a VPN to force a sign-up from another region. The cost of that usually does not land at the sign-up step, it lands when you try to get your money out (the risks of logging into an exchange over a VPN covers it in more detail). If you are in mainland China specifically, see whether Binance is still usable in mainland China.

Do not invert the order

Wallet first, account second. The reason is not tidiness, it is human nature: if the coins have no clear destination once bought, the overwhelming majority of people simply leave them where they are, and then they sit there for years. The destination has to exist before the withdrawal actually happens.

Walking the sign-up · where the referral code goes

The sign-up itself is not complicated; under normal conditions it takes a few minutes. Below it is broken out in order, with the places things go wrong marked.

Step one · reach the sign-up page through the right entrance

This step carries more risk than every step after it combined. A fake exchange login page is the most common form of phishing there is: the ad slot at the top of the search results, a shortened link forwarded on social media, a so-called exclusive channel posted in a chat group — any of them can drop you on a site that looks identical to the real one. Every character you type there, including the verification code that comes later, gets relayed to the real site in real time.

There are only two reliable habits: type the official domain by hand once, bookmark it, and afterwards only ever enter through the bookmark; or arrive through a link you trust and that you can see in full, and check the address bar the moment you land. For the real-world scripts, see the fake official site in a search ad slot and the fake Binance app on Android.

Affiliate disclosure · the entrance I use

Binance sign-up page · referral code BN16188

If you intend to use my referral code, you can go straight through this Binance sign-up page; the referral field on the page normally carries BN16188 automatically, and you should still check the characters yourself before submitting.

Disclosure: if you sign up through this link from the platform, and it adds nothing to your cost. The up to 20% fee rebate is the ceiling of that referral program; how much of it you actually get, and whether you qualify at all, depends on region, product line and account status, and everything is subject to Binance's current affiliate rules and what your own account page shows — please do not treat it as a fixed number you are guaranteed. This site is an independent affiliate, and the full boundaries of the relationship are written out on the disclosure page.

Step two · choose how to register

You can usually register with an email address or a phone number, and there may be a one-click option through a third-party account. My advice is use the email address. Email is the most controllable: it does not depend on your mobile carrier, it survives moving countries, and it makes for better paperwork if you ever have to appeal. Signing in through a third-party account looks convenient, and the price is that your exchange account is now attached to the security of another account, which is one more single point you do not control.

Step three · set the password

Paste in the string your password manager generated. Do not use "I can remember it" as the standard — not being able to remember it is the point, because remembering it is the password manager's job. While you are here, confirm one thing: does your password manager itself have a backup, and is the master password written down somewhere else as well?

Step four · enter the referral code

The sign-up form usually has a field called referral code, invite code or Referral ID, and that field is often collapsed, showing only a small line of text on the page until you click it open. If you arrived through a link carrying a ref parameter, it is normally filled in already, and your job is to expand it and check that the characters read BN16188.

Why insist on checking before you submit: whether it can be added after registration, and how long that window lasts, differs by region and by period, so I cannot give you an answer that stays true. Go by Binance's current rules and by the referral information shown in your account. The safe habit is simply to confirm it before submitting; the glance costs two seconds.

Step five · code, terms, submit

A verification code arrives by email or SMS. There is a habit to build here: you only ever type a verification code into an action you started yourself. Anyone asking you for a code in any situation — claiming to be support, claiming to be risk control, claiming to be helping you unfreeze something — is running a scam, with no exceptions. The full script of the fake support call is in this case study.

You do not have to read the terms word for word, but do at least skim the parts of the service agreement covering your own region, along with the sections on asset custody and where liability sits.

Step six · log in, and do nothing yet

Once registration succeeds, the first thing is not depositing and not buying, it is finishing the security settings — which is the next section. While you are in there, you can also check on the account information page whether the referral is recorded (how and where it appears depends on the platform's current pages).

Where to get the app

If you want the mobile app, search the official name in your device's own app store, or use the download entrance given on a website page you have already verified. Do not install a package forwarded in a chat group, and do not take one from whichever download site a search engine surfaces. A fake app can look indistinguishable from the real one, and the seed phrase and password you type into it go straight to somebody else's server.

The KYC gate · documents, liveness and why it gets rejected

Identity verification (KYC) is now a precondition for withdrawing, not an option. The global anti-money-laundering framework (AML) pushed this onto every licensed platform, so do not spend your energy looking for a way around it; doing it cleanly once is actually the fastest route.

Roughly which gates you pass through

The tiers and their names are not identical everywhere, but the flow generally has this skeleton: fill in basic details (name, date of birth, nationality, address), then upload the front and back of a document, then complete a liveness check (turn your head, blink or read out a string of digits as the screen prompts), and in some regions supply an additional proof of address or a source-of-funds statement. The higher the tier, the more limits and features open up.

On how long it takes, I will not give you a number. Automated approval is fast; anything that needs a human is noticeably slower, and slower still at peak times. What you can control is submitting correct material the first time, so there is no back and forth.

Common reasons for rejection, and how to fix each

The table below puts the common rejection situations next to what to do about them. It is not the platform's official taxonomy; it is grouped the way I have seen and heard these play out, and the exact wording you get is whatever your own account page shows.

The rejection Usually because How to fix it
Document photo not sharp Focus never locked, not enough light, or shaky hands Lay it flat on a table, use daylight, take it out of the plastic sleeve
Glare covering key details A ceiling light or flash hitting the laminate Turn the flash off and move the document to the side of the light source
Corners cropped off Framed too tight, so the four corners fell outside the shot Leave a margin so all four corners and the background pattern are in frame
Name does not match The spelling typed at sign-up differs from the document Change it to the spelling printed on the document, do not invent one
Document expired The expiry date passed without you noticing Renew it first; do not keep retrying with an expired document
A copy or a photo of a screen You shot a printout, a screen, or a photocopy The physical original has to be what is in the photo
Liveness check fails Moving too fast, too little light, wearing a hat or a mask Remove anything covering your face, light it from the front, follow the prompts slowly
Proof of address rejected The document is too old, or the name and address on it do not match what you typed Use a recent utility bill or bank statement, with all three details aligned

One more warning: submit the verification material yourself, and never hand it to any person or agency claiming they can get you verified. Giving a stranger both sides of your identity document plus a liveness video is handing over a complete kit for impersonating you — used later to open other accounts and sign up for other services, entirely without your knowledge.

If you have already passed and want to withdraw or cancel the verification, see whether KYC can be revoked. For the case where the account gets restricted after verification and more documents are demanded, what to do when an account is frozen lays out an order of operations.

Do not buy yet · four things to set immediately

A new account is at its most fragile exactly when it has just been opened and you are keen to make the first purchase. Not one security option is set yet, and the balance is about to arrive. The four things below add up to twenty minutes; do them before you deposit. For a hodler the first one matters more than the other three combined, which is why I moved it to the front.

One · the withdrawal allowlist, which exists for people like you

The logic of the withdrawal allowlist is that the account can only send coins to addresses you added to the list beforehand and confirmed. Everyday withdrawals are unaffected; the only thing it blocks is sending a large amount to an unfamiliar new address on the spot. Which is precisely what somebody who has taken over your account wants to do.

Its value to a hodler is far greater than to a trader, for a plain reason: your withdrawal destinations are the same one or two addresses over and over, so you never needed the ability to send to any address at any time in the first place. A trader finds the allowlist obstructive. You do not. So the most comfortable way to use it is this: add your own self-custody address to the allowlist before you buy your first coin, and turn on the cooling-off restriction for newly added addresses. From day one, the money leaving this account is locked onto a single path — back to you. Even if someone takes over your session one day, the most they can do is move your coins to your own wallet.

The companion switch for "fast withdrawal" (small withdrawals to allowlisted addresses without a second verification) is a matter of taste. Turn it on if you want the convenience; I leave it off and verify every time — I withdraw only a few times a year anyway.

Two · move two-factor off SMS

Two-factor is not a question of whether, it is a question of which. From weakest upward: SMS is the weakest, an authenticator app's rotating code (TOTP) sits in the middle, and passkeys and hardware security keys are the hardest. Set TOTP or a passkey as the primary method and keep SMS only as a fallback. When you enable TOTP, copy down that backup key and store it now, not later — if the phone is lost or the app is deleted by accident, that string is what restores it on a new device.

Three · set an anti-phishing code

Strictly speaking this one is not a lock; it stops nobody from logging into your account. It does something else: it turns "was this email really from the platform?" from a judgement call that takes experience into a check with only two possible answers. You set a string of characters, and from then on the platform's official emails to you carry it; the mass-mailed fakes have no idea what you chose, so they cannot reproduce it. Remember one thing: the code only ever appears in emails the platform sends you, so anyone who contacts you asking for your anti-phishing code is a scammer.

Four · go through devices, sessions and API keys

A new account needs this too. You may have logged in once on an office computer and tried it once on a friend's phone, and both traces are sitting in the device list. Anything you do not recognise or no longer use, remove it. The API key section is usually empty on a new account, but remember where it is — later on, after you have used some market-data tool or copy-trading script, come back and delete the key when you are done. An old key still carrying withdrawal permission is a back door that plenty of people have forgotten they left open.

These four are only the skeleton. For which layer actually blocks what — including the one among them that barely counts — see whether SMS two-factor can be cracked. The panorama of the phishing techniques themselves is in The phishing scam atlas, 2026 edition.

Something you can do right now

Once these four are set, run the hodler self-check and see where you score. The day you open the account is your baseline; run it again three months later and see whether you have slipped.

Your first deposit and your first purchase

Which deposit methods are available depends on where you are — bank card, third-party payment, peer-to-peer trading (P2P) and so on. Which ones this particular account can use is whatever the page shows you; do not copy someone else's experience.

P2P deserves a warning. The price of its convenience is that the money reaching you comes from another individual, and if that money has a problem behind it, your bank card can be caught up and frozen. This is not rare, and it is draining to deal with. If you do go that route, favour counterparties with high volume and complete verification, keep the full chat and transfer records, and do not receive the funds on your salary account. The detailed response is in what to do when a P2P payment gets your bank card frozen.

The buying step is the easy part for a long-term holder: a market order fills straight away, or a limit order sits at a price you would be happy with. There is no need to study technical analysis here — you came to accumulate, not to trade. The thing genuinely worth your attention is in the next section.

There are also two small habits that will save you a lot later if you build them now:

  • Keep your own records. The time, quantity, unit price and fee of every transaction, written down separately by you. The platform's history has a retention limit, and if something goes wrong with the account you may not be able to pull it at all. Tax filing, cost basis, a portfolio review years from now — all of them need that record. Tax treatment varies enormously by country; do you pay tax on crypto is a place to start forming a picture.
  • Small before large. The first time you walk the whole path (deposit, buy, withdraw to your own wallet), do it with an amount so small you would not care about losing it. Once the path works, go back to your planned amount. That small rehearsal exposes every snag you did not anticipate.

Discipline after you buy · when to move out, what to check first

This section is the most important one in the article. Every step before it exists to get you here — turning coins from rows in a platform's database into a balance controlled by your own private key.

When to withdraw

Rather than fixing an absolute amount, set three trigger lines and act when any one of them is met:

  1. The balance goes above the number you gave yourself in question two. That "would sting but would not change my life" ceiling you wrote down: cross it and withdraw.
  2. You do not plan to touch these coins any time soon. The standard can be loose — say, no intention of selling or swapping in the next month. If you are not touching them, there is no reason for them to sit on the platform.
  3. You have finished this round of buying. If you buy regularly, consolidate monthly or quarterly and withdraw once, which saves both fees and hassle.

The other way round, what can stay: the portion you genuinely intend to trade soon, and the small amount you keep for cashing out. Those two are reasonable to leave.

Six things to check before every withdrawal

Withdrawals are irreversible. Once an on-chain transaction is packed into a block, no support agent can pull it back (why it cannot be undone is in whether a mistyped withdrawal address can be recovered). So run these six every time, and do not get bored of them.

Check What exactly to look at
Where the address came from The address was copied out of your own wallet, not out of a chat log, an email or a screenshot
The address itself After pasting, compare several characters at the start and at the end. Clipboard malware exists specifically to swap the address at this step
Network / chain The chain selected on the withdrawal side must be the same chain your receiving wallet supports
Allowlist The destination is already on the allowlist and past the cooling-off period for newly added addresses
Small test first The first time you send to a new address, send a small amount, confirm it arrived, then send the rest
Backup verified You have actually restored the destination wallet's seed phrase once on another device

That last one is the most often skipped and the most severe when it bites. A backup you have never verified you can restore from is not a backup. The correct order is: initialise the wallet, write down the seed phrase, restore from that seed phrase once on another device or on the same device after a reset, confirm the addresses match, and only then send money in. That process and the choice of storage medium are covered closely in Five ways to store a 24-word seed phrase and Private keys and seed phrases.

Picking the wrong network is the other frequent way people come unstuck. The same token on different chains is a different contract, and getting it wrong means a recovery process at best and nothing back at worst — Can USDT sent on the wrong chain be recovered? takes that apart specifically. While you are checking the address, check the network field in the same pass; it takes two seconds.

What I actually do

I have one unchanging habit around withdrawals: no matter the size, the first transfer is always a small test, and only once the wallet end confirms receipt and the leading and trailing characters match exactly do I send the rest. I have never skipped that step, not even sending to an address I have used for two years.

One more detail: I do not withdraw when I am in a hurry. Rushing is when people skip steps — thinking "I have sent to this address plenty of times" and pasting it straight in. The moments things actually go wrong tend to be the moments you feel most practised.

After the withdrawal

Once it arrives, check on a block explorer that the balance shown in the wallet matches what is on chain. Then put the transaction hash and the date into your own ledger. Only when that is done has the asset really landed in your own pocket.

Keeping a dormant account healthy

Once the coins are out, this account settles into a long low-frequency state — maybe one login every few months. That sounds harmless, but an idle account quietly accumulates a few problems that all surface together on the day you genuinely need it (which is usually the day you need it urgently).

The things that tend to break are these: the phone number you bound is out of service; the authenticator app never made it across when you changed phones; the document expired without being renewed; the platform's rules or verification requirements changed without you knowing; some third-party authorisation you forgot about is still active.

Ten minutes once a quarter

Item What to look at
Log in once Confirm you still remember the password, two-factor still works, and there is no pending notice on the account
Email and phone number Confirm both channels can still receive the platform's verification messages
Allowlist The addresses are still the ones you use now; if you changed wallets, delete the old address
Devices and sessions Remove devices you no longer use and check the login history for anything that does not line up
API keys Delete anything you no longer use, especially anything carrying withdrawal permission
Document expiry Renew ahead of time rather than discovering it on the day you need to cash out
Account balance Confirm that occasional odds and ends have not quietly built back into a balance that should not be sitting there

What to do before changing phone, number or country

These three are the most common triggers for an idle account going wrong, and the order is the same in all three cases: while the old device still works, migrate the bindings first, and only then deal with the old device.

New phone: install the authenticator app on the new one, restore it with the backup key, confirm it produces correct codes, and only then wipe the old phone. New number: change and verify the bound number on the platform first, then cancel the old one. Moving country: confirm the service availability and verification requirements for your new address first, rather than discovering the problem when a new proof of address is demanded.

And a restatement of what this account is for

The point of maintaining the account is to keep the channel open for when you need it, not to turn it into somewhere worth putting things. For judging whether a platform deserves custody of anything, I listed six dimensions you can verify yourself in the exchange evaluation handbook; for the warning signs a platform usually gives before it fails, the signs an exchange is about to run has them collected. Read those two and you will see why I keep insisting the balance stays low.

Common questions

I just want to hold. Can I avoid exchanges entirely?

In theory yes, in practice almost nobody manages it. You can buy over the counter from someone you know, you can swap on a decentralized exchange, but the fiat end always needs an exit, unless your coins were mined or paid to you directly. The more realistic approach is to treat the exchange as a port rather than a warehouse: open one account, set every security option, withdraw to your own wallet as soon as you buy, and keep only a very small balance there long term. That way, if the platform blows up, what you lose is that small balance plus some hassle, not everything you own.

After I submit, how do I confirm the referral was actually recorded?

The cheapest confirmation happens before you submit: the referral field on the sign-up form is often collapsed, so you have to click it open to see it, and it is usually filled in automatically when you arrive through a link carrying a ref parameter. Expand it and check that the characters read BN16188. If you have already submitted, look at your account information or the referral-related pages to see whether it is recorded; where it appears and what the field is called depend on the platform's current pages. As for whether it can be added after registration and how long that window lasts, the rules differ by region and by period, so go by Binance's current rules and the referral information shown in your account. The up to 20% fee rebate is the ceiling of that program, and the actual share depends on product line, region and account status, so do not treat it as a fixed number.

Is KYC mandatory? Can I withdraw without it?

Major exchanges now tie identity verification to withdrawals, and an unverified account can do very little. Rather than looking for a way around it, do it cleanly in one pass: a document still within its validity period, a name matching the document exactly, photos that do not cut off the corners, and a liveness check done slowly, following the prompts. If your name contains unusual characters or can be transliterated more than one way, use the spelling printed on the document and do not invent a prettier one. Which materials your region requires and how the tiers are divided are matters for Binance's current verification flow and the prompts on your own account page.

Can I use a VPN to sign up from another region?

I would not, and the cost of doing it usually does not land at the sign-up step, it lands when you try to get your money out. Registration may go through smoothly, but when you withdraw, cash out, or get asked for extra documents by risk control, a login location, a document nationality and a bank record that do not line up will get the account restricted, and you will be in a very weak position. Whether this exchange can be used normally where you live is something to settle before you open the account, not something to work around after.

If I withdraw right after buying, is the fee wasted?

A withdrawal costs an on-chain fee, and the amount depends on the network you pick. But look at what that fee buys: these coins no longer depend on one company staying in business. For someone planning to hold for years, that one-off cost spread across those years is small. What you should economise on is frequency. Do not withdraw three times a day; let it accumulate to a sensible amount and withdraw once, which also spreads out the cost of the small test transfer.

If the account sits untouched for a long time, will it be closed or charged?

Not logging in for a long time does not usually get an account closed by itself, but it stacks up several problems: the phone number you bound is out of service, the authenticator app was lost when you changed phones, the document expired, the platform's rules changed without you knowing. Put those together and, on the day you actually need the account, you may have to go through a long appeals process. My own habit is to log in once a quarter and run through the allowlist, the device list and the verification methods while I am there. On fees, go by Binance's current announcements and your own account page.

Last word

Back to the tension I opened with. This site talks about self-custody constantly and has just published a sign-up guide — I do not think there is a contradiction in that. You need a door in order to get from the fiat world to the on-chain world. This piece was about hanging that door solidly: a dedicated email address, hard two-factor, an anti-phishing code, and the allowlist that matters most of all.

But once the door is hung, what decides the outcome is whether you walk through it. However complete your security settings are, they can only stop attacks aimed at you personally; risk at the platform level is not something any setting can block. There is only one solution to that, and it is moving the coins somewhere your own private key controls.

However neatly the account is set up, all you have done is hang the door. Leaving the coins in the doorway and taking them home are two different things.

If you do only one thing today: go and get the self-custody wallet ready, and verify once that the backup restores. Do that, then come back and open the account, and your order will be right. If you would rather work through it day by day, the 30-day learning path breaks these actions into half an hour a day.